Anthropic Accused DeepSeek Of Secretly Using Claude + 6 More Labs
Universe of AI · 2026-09-15 · community · 14,880 views
What's in the video
Description written by Gemini, which watched and listened to the whole video.
Summary
The presenter from the channel Universe of AI reviews Anthropic’s fourth threat intelligence report ("Detecting and countering misuse of AI: September 2026"). The video breaks down the report’s major disclosures, focusing on advanced AI-assisted cyber operations, illicit model distillation and prompt proxying by major Chinese AI labs (notably Alibaba, Moonshot AI, and DeepSeek), and real-world AI misuse across surveillance, influence, and weapons design.
What is shown
- [00:00] Anthropic’s official post on X announcing its comprehensive threat intelligence report detailing misuse of Claude and naming seven Chinese AI labs engaged in illicit distillation.
- [00:50] The Anthropic website landing page for "Detecting and countering misuse of AI: September 2026", showing report sections: Cyber operations, Surveillance operations, Influence operations, Conventional weapons, Biological misuse, Scams and fraud, and Illicit distillation.
- [01:38] The report section "AI-augmented cyber operations: From assistant to orchestrator", covering tracked threat groups like GTG-20006 (linked to Russian state-sponsored operations/Midnight Blizzard) and autonomous malware rewriting loops.
- [04:38] A promotional overlay for the Universe of AI newsletter and community website.
- [04:47] Case study for GTG-50029, detailing a solo French hacktivist who scanned for exposed API keys, exploited WordPress, exfiltrated voter and political records, and published searchable datasets on the dark web.
- [06:17] Infographic titled "Anatomy of a distillation campaign" (Manufacture identities $\rightarrow$ Harvest $\rightarrow$ Clean $\rightarrow$ Train).
- [06:43] Breakdown of distillation cases by Chinese labs: GTG-16005 (Alibaba / Qwen), GTG-16002 (Moonshot AI / Kimi), and GTG-16001 (DeepSeek).
- [08:40] Review of broader cases in the report, including influence campaigns, a carrier-wide surveillance system in Mali, conventional weapons drafting, and automated fake dating applications.
- [10:01] Channel outro displaying the Universe of AI and World of AI YouTube channels, newsletter site, and X profile.
Claims & numbers
- Anthropic published a 154-page threat intelligence report spanning detected misuse between December 2025 and August 2026 across roughly 40 tracked threat groups (the presenter says).
- The presenter claims all misuse cases ran on Claude Haiku, Sonnet, or Opus models, with no Fable- or Mythos-class models involved except in the distillation section.
- In cyber operations, the presenter states AI has collapsed the gap between well-funded state operations and an individual attacker operating alone.
- In the GTG-20006 operation, an actor targeted over 20 organizations (Ukrainian and European governments, embassies, defense firms, drone manufacturers), compromised hotel Wi-Fi networks, and exfiltrated over 300,000 national ID records from a North African government (the presenter says).
- GTG-50029 (a solo French operator) compromised 14 of 42 targeted political entities and think tanks, exfiltrating roughly 140,000 political records and publishing tens of millions of cross-referenced rows on the dark web (the presenter says).
- Alibaba allegedly carried out the largest illicit distillation campaign observed, logging over 151 million exchanges between May and July 2026 (peaking near 3 million daily across ~5,000 fraudulent accounts) to train Qwen 3.5, 3.6, and 3.7 (the presenter says).
- Anthropic alleges Moonshot AI logged over 23 million exchanges, DeepSeek logged over 12.1 million exchanges in 14 days, Zhipu logged over 3 million, and Xiaomi logged over 400,000 requests (the presenter says).
- Anthropic claims Moonshot and DeepSeek silently proxied user queries to Claude (including Opus) instead of running their own models to capture transcripts for training (the presenter says).
- To counter distillation, Anthropic implemented internal reasoning summarization before outputting responses and added "preserve thinking" in Claude Fable 5.1 (the presenter says).
- Additional tracked incidents include 9 influence operations across 6 continents (including a French ad agency operating ~70 fake news sites), a Mali surveillance tool targeting 25 million SIM cards, 6 conventional weapons cases, and a Chinese studio running 20+ dating apps using 4,700 AI personas engaging 25,000 users (the presenter says).
Notable quotes
- "AI has collapsed the gap between a well-funded state operation and one person in a bedroom." [01:46]
- "They had agents monitoring whether security products had flagged their malware. When something got detected, the agents would rewrite and rebuild it automatically..." [03:39]
- "Moonshot was silently forwarding its own customers' requests to Claude, then showing those users Claude's answers as if Kimi produced them..." [07:42]
Assessment
This is an independent YouTube commentary and breakdown video summarizing Anthropic's published threat intelligence report. The creator does not demonstrate hands-on exploits or independent technical tests, instead visually navigating Anthropic's public report pages and reading through its disclosed telemetry and findings.
Described by gemini-3.8-flash on 2026-09-29 from the video's audio and frames.