Anthropic accuses DeepSeek, Moonshot and MiniMax of 'distillation attacks': 16M+ Claude exchanges via ~24,000 fraudulent accounts
On Feb 23, 2026 Anthropic published "Detecting and preventing distillation attacks", saying three Chinese AI labs (DeepSeek, Moonshot AI and MiniMax) had generated over 16 million exchanges with Claude through about 24,000 fraudulent accounts to extract its agentic reasoning, tool-use and coding abilities for training their own models. It was the first time a US lab named rivals in a distillation campaign, and it set up the larger Alibaba accusation in June and the seven-lab list in the September threat report.
Key facts
- Per lab (Anthropic): DeepSeek over 150,000 exchanges, Moonshot AI over 3.4 million, MiniMax over 13 million; total over 16 million via ~24,000 fraudulent accounts
- Method: 'hydra cluster' networks of proxy services and fraudulent accounts to get around Anthropic's ban on access from China; attribution 'with high confidence' through IP address correlation, request metadata and infrastructure indicators
- Targets: agentic reasoning, tool use and coding, which Anthropic calls Claude's most differentiated capabilities
- MiniMax's campaign was caught while active; when a new Claude model launched, MiniMax 'pivoted within 24 hours, redirecting nearly half their traffic' to it
- Response: classifiers and behavioral fingerprinting for distillation patterns (incl. chain-of-thought elicitation), stricter verification for education, security-research and startup accounts, sharing indicators with other labs, cloud providers and authorities, and model-level safeguards; 'no company can solve this alone'
- Follow-ups: Alibaba's Qwen lab accused of a larger campaign (28.8M exchanges, June 2026); the Sept 2026 threat report named seven China-based labs
What happened
Anthropic published a security post that described coordinated campaigns by three Chinese labs to query Claude at scale through fake accounts and proxy resellers, harvest its outputs and use them as training data. It named the labs, gave per-lab exchange counts and listed its countermeasures.
Why it matters
"Distillation attacks" became a named security and policy issue in 2026. The report framed copying a frontier model's outputs as theft of capabilities rather than ordinary competition, and later US moves (the April OSTP distillation memo, the Hagerty–Kim sanctions proposal) built on that framing.
Changelog
- 2026-10-04: created (found while resolving the Oct 4 sweep item on Anthropic's Alibaba letter; pre-cutoff background)
Related events
- Anthropic tells US senators and the White House that Alibaba's Qwen lab ran the largest known distillation campaign on Claude (28.8M exchanges) ★★★
- Anthropic threat intelligence report: AI-orchestrated cyberattacks and distillation by Chinese labs ★★★
- China's cyberspace regulator probes DeepSeek and Moonshot over possible data leaks to Anthropic via Claude ★★★
- Anthropic says it has never advocated a ban on open-weights models, after Jensen Huang's industry letter ★★★
Sources (3)
- officialAnthropic: Detecting and preventing distillation attacks (Feb 23, 2026)
- pressInfosecurity Magazine: Chinese AI firms hit Claude with distillation attacks, Anthropic warns
- discussionHacker News discussion
id: 2026-02-23-anthropic-distillation-attacks-report · updated 2026-10-04 · open in the interactive timeline