Observed Signal · Feb 23, 2026 · Security Incident · Source: techcrunch · Impact: 4/5 · Sentiment: Negative
Anthropic Blames Chinese Labs for AI Model Theft
Anthropic alleges three Chinese AI companies—DeepSeek, Moonshot AI and MiniMax—created more than 24,000 fake accounts to query its Claude model, generating over 16 million exchanges using a technique called "distillation" to improve their own models. Anthropic says the exchanges targeted Claude’s agentic reasoning, tool use and coding capabilities, and that the scale of extraction suggests access to advanced AI chips. The accusations arrive amid U.S. debates over export controls after the administration recently allowed exports of advanced chips (e.g., Nvidia H200) to China. Anthropic plans to invest in defenses against distillation attacks and is calling for a coordinated response from industry, cloud providers and policymakers, warning of potential national-security risks if safeguards are stripped from illicitly distilled models.
Allegations of large-scale illicit model extraction affect foundation model safety, national-security concerns, and reinforce debates over export controls for advanced AI chips—outcomes that could influence industry policy, cloud providers and hardware export rules.
Track Anthropic Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Anthropic accused DeepSeek, Moonshot AI and MiniMax of creating more than 24,000 fake accounts to interact with Claude.
- Anthropic said the three labs generated over 16 million exchanges with Claude using distillation.
- Anthropic reported exchange counts by lab: DeepSeek (~150,000+ exchanges), Moonshot AI (~3.4 million exchanges), and MiniMax (~13 million exchanges).
- The article notes the U.S. recently allowed exports of advanced AI chips (such as Nvidia's H200) to China, a topic under debate.
- Anthropic called for coordinated defenses involving the AI industry, cloud providers, and policymakers to make distillation attacks harder to execute and detect.
Connected Companies & Entities
4 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Anthropic Accuses Chinese Firms of AI Distillation Attacks
Anthropic accused three Chinese AI companies—DeepSeek, Moonshot AI and MiniMax—of coordinated 'distillation attack' campaigns that extracted capabilities from its Claude model by flooding it with specially crafted prompts. Anthropic said the firms used commercial proxy services to bypass access restrictions and estimated more than 16 million exchanges with Claude from roughly 24,000 fraudulently created accounts; MiniMax accounted for over 13 million exchanges. The complaints follow similar allegations from OpenAI about DeepSeek. Both companies framed the activity as a national security and intellectual-property concern, and Reuters reported U.S. officials found evidence DeepSeek trained a model on Nvidia’s Blackwell chip. Industry experts noted distillation is a common technique but said the controversy centers on alleged fraudulent access and possible violations of terms of service.
Anthropic accuses Chinese labs of stealing Claude via distillation
Anthropic's threat intelligence head, Jacob Klein, reports that Chinese AI labs, including Alibaba, Moonshot (Kimi), and DeepSeek, are illicitly using its Claude models via distillation to train cheaper competitors. The report details unauthorized distillation involving fraudulent accounts and stolen credit cards. Alibaba's operation peaked at 3 million daily exchanges from 3,500 fraudulent accounts to train Qwen models, while Moonshot routed ~300,000 Kimi user requests to Claude using 5,380 fake accounts, and DeepSeek conducted over 12 million attacks. The practice also exposed sensitive data, including surveillance footage of Chinese military sites and Russian government credentials. Anthropic says these actions violated terms and privacy laws, raising national security concerns. The Trump administration has called such distillation 'unacceptable,' and Anthropic, valued near $1 trillion, plans an IPO as early as October.
Anthropic Accuses Alibaba of Spying on Claude
Anthropic has told U.S. senators it believes attackers linked to Alibaba tried to illicitly extract capabilities from its Claude model via so‑called "distillation" attacks. In a letter published by the Financial Times, Anthropic alleges nearly 25,000 fraudulent accounts accessed Claude almost 29 million times between late April and early June to learn about the model's structure and task logic. Anthropic is calling for stronger U.S. laws to prevent such attacks, permission for American AI firms to warn one another, and tighter limits on Chinese access to AI technologies (including chips). Alibaba has not commented. The piece also notes related industry context: Elon Musk admitted using distillation for his Grok chatbot and Anthropic recently faced U.S. government action requiring the temporary removal of its Fable 5 software from the market.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
