Anthropic Accuses Chinese AI Labs of 16 Million Query Distillation Attack on Claude
Anthropic identified industrial-scale distillation campaigns by DeepSeek, Moonshot AI, and MiniMax using 24,000 fake accounts and 16 million queries to extract Claude's capabilities. The accusations mirror OpenAI's earlier claims and raise urgent questions about AI intellectual property protection.
Executive Summary
Anthropic has publicly accused three Chinese AI laboratories — DeepSeek, Moonshot AI, and MiniMax — of orchestrating industrial-scale data extraction campaigns against its Claude AI model. The operation involved more than 24,000 fraudulent accounts generating over 16 million exchanges with Claude, all designed to systematically harvest the model's capabilities through a technique known as distillation. The revelation, first reported by TechCrunch and confirmed by CNBC, arrives as the United States intensifies its debate over AI chip exports to China and marks the second major American AI company to level such charges.
Total Fake Accounts
24,000+
created across three Chinese AI labs
The Accusations
Anthropic's security team identified three distinct but simultaneous distillation campaigns targeting Claude's most advanced capabilities. Each Chinese lab focused on different aspects of the model's intelligence, suggesting a coordinated effort to reverse-engineer Claude's full capability stack.
DeepSeek generated more than 150,000 exchanges specifically targeting Claude's foundational logic and alignment systems. These queries were designed to probe how Claude reasons through complex problems and how its safety training shapes its responses — the architectural DNA of the model.
Moonshot AI ran the second-largest campaign with over 3.4 million exchanges focused on agentic reasoning and tool use. This targeted Claude's ability to plan multi-step tasks, use external tools, and operate autonomously — capabilities that represent the frontier of current AI development.
MiniMax conducted the most aggressive extraction, executing more than 13 million exchanges that targeted agentic coding and tool use capabilities. At roughly 80% of the total query volume, MiniMax's operation suggests a massive compute investment in the distillation effort.
| lab | queries |
|---|---|
| DeepSeek | 0.15 |
| Moonshot AI | 3.4 |
| MiniMax | 13 |
What Is Distillation and Why It Matters
Distillation is a legitimate machine learning technique in which a smaller, less capable model is trained on the outputs of a larger, more capable one. AI companies routinely use distillation internally to create efficient versions of their flagship models. OpenAI's GPT-4o Mini and Anthropic's own Haiku models were created using forms of distillation from their respective parent models.
The technique becomes illicit when competitors use it to extract capabilities from rival systems. By generating millions of carefully crafted prompts and collecting Claude's responses, these labs were effectively using Anthropic's model as a teacher to train their own systems — without permission, without payment, and in violation of Anthropic's terms of service.
Legitimate vs. Illicit Distillation
Internal Distillation
Cross-Company Extraction
The strategic value of this approach is significant. Training frontier AI models from scratch requires billions of dollars in compute and years of research. Distillation from a more capable model can shortcut this process dramatically, allowing a less-resourced lab to achieve similar performance at a fraction of the cost. For Chinese AI labs facing chip export restrictions that limit their access to cutting-edge training hardware, distillation from American models represents an alternative path to competitive capabilities.
A Pattern Emerges
Anthropic is not the first major American AI company to make these accusations. OpenAI raised similar concerns about Chinese firms in late 2025, specifically flagging DeepSeek's distillation activities. As reported by CNN, Anthropic now joins OpenAI in documenting what both companies describe as "industrial-scale" distillation campaigns originating from Chinese laboratories.
The parallel accusations create a pattern that extends beyond individual company grievances into a broader industry and national security concern. If two of America's leading AI companies have independently identified systematic extraction campaigns from the same set of Chinese labs, it suggests an organized effort rather than isolated incidents.
OpenAI Flags DeepSeek
OpenAI first raises concerns about Chinese distillation attacks on its models
DeepSeek R1 Launch
DeepSeek releases R1 reasoning model, disrupting the market with competitive performance at lower cost
Anthropic Goes Public
Anthropic publicly accuses DeepSeek, Moonshot AI, and MiniMax of 16M-query distillation campaign
CNBC Confirms Pattern
CNBC reports both Anthropic and OpenAI now flagging same Chinese firms for industrial-scale extraction
This is particularly significant in the context of DeepSeek's rapid rise. When DeepSeek launched its R1 reasoning model in January 2026, many analysts were surprised by its competitive performance given China's hardware constraints. Anthropic's accusations now raise questions about how much of that performance was achieved through legitimate innovation versus extracted capabilities.
The Geopolitical Dimension
The timing of Anthropic's disclosure is not coincidental. The United States is actively debating whether to further tighten AI chip export restrictions to China. The Biden-era controls on NVIDIA's advanced GPUs have been a point of contention, with some arguing they are insufficient and others warning they push China toward domestic alternatives.
Anthropic's public accusation provides ammunition for those advocating stricter controls. If Chinese labs cannot access cutting-edge hardware to train models from scratch, and they are instead stealing capabilities from American models through distillation, it undermines the argument that chip restrictions are effectively containing China's AI advancement.
As CyberScoop reported, the distillation campaigns also raise cybersecurity concerns. The 24,000 fraudulent accounts required sophisticated identity fabrication, payment processing through third-party channels, and operational security to avoid detection across millions of queries. This is not casual misuse — it is a structured intelligence-gathering operation with significant resource investment.
DeepSeek Focus
150K+
exchanges targeting alignment systems
Market Context: Anthropic's Devastating February
The distillation revelations cap a February that has established Anthropic as the most market-disrupting force in AI. Just days before the Chinese lab accusations, Anthropic's COBOL modernization tool announcement triggered IBM's worst stock drop since 2000 — a 13.2% single-day plunge that extended IBM's monthly decline to 27%.
The broader SaaSpocalypse that began with Claude Cowork has wiped hundreds of billions from enterprise software valuations. Cybersecurity stocks including CrowdStrike and Datadog also slumped as investors assessed Anthropic's expanding threat to incumbent software businesses.
| event | impact |
|---|---|
| Claude Cowork (SaaSpocalypse) | 285 |
| COBOL Tool (IBM crash) | 18 |
| AI Fluency Index | 0 |
| Chinese Distillation | 0 |
In the same week, Anthropic also released its AI Fluency Index — a groundbreaking study analyzing nearly 10,000 conversations to measure human-AI collaboration effectiveness. The sheer volume and significance of Anthropic's February output positions the company as the pace-setter for the entire AI industry.
What Comes Next
Several implications follow from Anthropic's disclosure:
Legal action is likely. Anthropic has documented specific companies, specific account volumes, and specific capability targets. This level of detail typically precedes formal legal proceedings or regulatory complaints. Whether Anthropic pursues U.S. courts, international trade commissions, or direct diplomatic channels remains to be seen.
Detection systems will proliferate. Both Anthropic and OpenAI will invest in more sophisticated distillation detection — analyzing query patterns, identifying coordinated account behavior, and potentially watermarking model outputs to trace unauthorized redistribution.
Export controls debate intensifies. Congressional leaders advocating for stricter AI export restrictions now have concrete evidence from two major American AI companies documenting systematic capability extraction by Chinese competitors.
Trust in Chinese AI benchmarks erodes. If distillation from American models contributed to Chinese labs' benchmark performance, the competitive analysis frameworks that investors and enterprises use to evaluate AI capabilities become unreliable. My prediction on Chinese AI reaching 40% global developer mindshare may need to be reassessed in light of these allegations.
API pricing and access models change. Expect all major AI providers to implement stricter rate limiting, usage pattern analysis, and identity verification for API access. The era of relatively open AI model access may be ending.
Conclusion
Anthropic's accusation against DeepSeek, Moonshot AI, and MiniMax represents a watershed moment in the AI industry's relationship with intellectual property, national security, and international competition. The 16 million-query extraction campaign is not a gray area — it is systematic capability theft at industrial scale, conducted through fraudulent accounts and designed to circumvent legitimate competitive dynamics.
The question is no longer whether AI model distillation is happening across borders. It is whether the industry and policymakers can develop effective countermeasures before the next generation of capabilities is similarly extracted.
Sources
- TechCrunch: Anthropic accuses Chinese AI labs of mining Claude
- CNBC: Anthropic joins OpenAI in flagging distillation campaigns
- CNN: Are Chinese AI labs cheating?
- The Hacker News: 16 million Claude queries
- CyberScoop: Anthropic accuses Chinese labs
- SiliconANGLE: Anthropic slams Chinese AI firms
- Bloomberg: IBM sinks most since 2000