← Back to News
ANALYSIS

Anthropic Accuses Chinese AI Labs of 16 Million Query Distillation Attack on Claude

Anthropic identified industrial-scale distillation campaigns by DeepSeek, Moonshot AI, and MiniMax using 24,000 fake accounts and 16 million queries to extract Claude's capabilities. The accusations mirror OpenAI's earlier claims and raise urgent questions about AI intellectual property protection.

By Michael Eakins•• min read
AnthropicAI SecurityChinaDeepSeekDistillationIP TheftGeopolitics

Executive Summary

Anthropic has publicly accused three Chinese AI laboratories — DeepSeek, Moonshot AI, and MiniMax — of orchestrating industrial-scale data extraction campaigns against its Claude AI model. The operation involved more than 24,000 fraudulent accounts generating over 16 million exchanges with Claude, all designed to systematically harvest the model's capabilities through a technique known as distillation. The revelation, first reported by TechCrunch and confirmed by CNBC, arrives as the United States intensifies its debate over AI chip exports to China and marks the second major American AI company to level such charges.

Total Fake Accounts

24,000+

created across three Chinese AI labs

↑ 16%million queries extracted

The Accusations

Anthropic's security team identified three distinct but simultaneous distillation campaigns targeting Claude's most advanced capabilities. Each Chinese lab focused on different aspects of the model's intelligence, suggesting a coordinated effort to reverse-engineer Claude's full capability stack.

DeepSeek generated more than 150,000 exchanges specifically targeting Claude's foundational logic and alignment systems. These queries were designed to probe how Claude reasons through complex problems and how its safety training shapes its responses — the architectural DNA of the model.

Moonshot AI ran the second-largest campaign with over 3.4 million exchanges focused on agentic reasoning and tool use. This targeted Claude's ability to plan multi-step tasks, use external tools, and operate autonomously — capabilities that represent the frontier of current AI development.

MiniMax conducted the most aggressive extraction, executing more than 13 million exchanges that targeted agentic coding and tool use capabilities. At roughly 80% of the total query volume, MiniMax's operation suggests a massive compute investment in the distillation effort.

Bar chart data
labqueries
DeepSeek0.15
Moonshot AI3.4
MiniMax13

What Is Distillation and Why It Matters

Distillation is a legitimate machine learning technique in which a smaller, less capable model is trained on the outputs of a larger, more capable one. AI companies routinely use distillation internally to create efficient versions of their flagship models. OpenAI's GPT-4o Mini and Anthropic's own Haiku models were created using forms of distillation from their respective parent models.

The technique becomes illicit when competitors use it to extract capabilities from rival systems. By generating millions of carefully crafted prompts and collecting Claude's responses, these labs were effectively using Anthropic's model as a teacher to train their own systems — without permission, without payment, and in violation of Anthropic's terms of service.

Legitimate vs. Illicit Distillation

Internal Distillation

SourceOwn models
PurposeCreate efficient variants
Legal statusStandard practice
ExampleGPT-4o Mini from GPT-4o

Cross-Company Extraction

SourceCompetitor models
PurposeSteal capabilities
Legal statusTOS violation / IP theft
ExampleMiniMax from Claude

The strategic value of this approach is significant. Training frontier AI models from scratch requires billions of dollars in compute and years of research. Distillation from a more capable model can shortcut this process dramatically, allowing a less-resourced lab to achieve similar performance at a fraction of the cost. For Chinese AI labs facing chip export restrictions that limit their access to cutting-edge training hardware, distillation from American models represents an alternative path to competitive capabilities.

A Pattern Emerges

Anthropic is not the first major American AI company to make these accusations. OpenAI raised similar concerns about Chinese firms in late 2025, specifically flagging DeepSeek's distillation activities. As reported by CNN, Anthropic now joins OpenAI in documenting what both companies describe as "industrial-scale" distillation campaigns originating from Chinese laboratories.

The parallel accusations create a pattern that extends beyond individual company grievances into a broader industry and national security concern. If two of America's leading AI companies have independently identified systematic extraction campaigns from the same set of Chinese labs, it suggests an organized effort rather than isolated incidents.

Late 2025

OpenAI Flags DeepSeek

OpenAI first raises concerns about Chinese distillation attacks on its models

Jan 2026

DeepSeek R1 Launch

DeepSeek releases R1 reasoning model, disrupting the market with competitive performance at lower cost

Feb 23, 2026

Anthropic Goes Public

Anthropic publicly accuses DeepSeek, Moonshot AI, and MiniMax of 16M-query distillation campaign

Feb 24, 2026

CNBC Confirms Pattern

CNBC reports both Anthropic and OpenAI now flagging same Chinese firms for industrial-scale extraction

This is particularly significant in the context of DeepSeek's rapid rise. When DeepSeek launched its R1 reasoning model in January 2026, many analysts were surprised by its competitive performance given China's hardware constraints. Anthropic's accusations now raise questions about how much of that performance was achieved through legitimate innovation versus extracted capabilities.

The Geopolitical Dimension

The timing of Anthropic's disclosure is not coincidental. The United States is actively debating whether to further tighten AI chip export restrictions to China. The Biden-era controls on NVIDIA's advanced GPUs have been a point of contention, with some arguing they are insufficient and others warning they push China toward domestic alternatives.

Anthropic's public accusation provides ammunition for those advocating stricter controls. If Chinese labs cannot access cutting-edge hardware to train models from scratch, and they are instead stealing capabilities from American models through distillation, it undermines the argument that chip restrictions are effectively containing China's AI advancement.

As CyberScoop reported, the distillation campaigns also raise cybersecurity concerns. The 24,000 fraudulent accounts required sophisticated identity fabrication, payment processing through third-party channels, and operational security to avoid detection across millions of queries. This is not casual misuse — it is a structured intelligence-gathering operation with significant resource investment.

DeepSeek Focus

150K+

exchanges targeting alignment systems

↓ 100%probing safety training architecture

Market Context: Anthropic's Devastating February

The distillation revelations cap a February that has established Anthropic as the most market-disrupting force in AI. Just days before the Chinese lab accusations, Anthropic's COBOL modernization tool announcement triggered IBM's worst stock drop since 2000 — a 13.2% single-day plunge that extended IBM's monthly decline to 27%.

The broader SaaSpocalypse that began with Claude Cowork has wiped hundreds of billions from enterprise software valuations. Cybersecurity stocks including CrowdStrike and Datadog also slumped as investors assessed Anthropic's expanding threat to incumbent software businesses.

Bar chart data
eventimpact
Claude Cowork (SaaSpocalypse)285
COBOL Tool (IBM crash)18
AI Fluency Index0
Chinese Distillation0

In the same week, Anthropic also released its AI Fluency Index — a groundbreaking study analyzing nearly 10,000 conversations to measure human-AI collaboration effectiveness. The sheer volume and significance of Anthropic's February output positions the company as the pace-setter for the entire AI industry.

What Comes Next

Several implications follow from Anthropic's disclosure:

Legal action is likely. Anthropic has documented specific companies, specific account volumes, and specific capability targets. This level of detail typically precedes formal legal proceedings or regulatory complaints. Whether Anthropic pursues U.S. courts, international trade commissions, or direct diplomatic channels remains to be seen.

Detection systems will proliferate. Both Anthropic and OpenAI will invest in more sophisticated distillation detection — analyzing query patterns, identifying coordinated account behavior, and potentially watermarking model outputs to trace unauthorized redistribution.

Export controls debate intensifies. Congressional leaders advocating for stricter AI export restrictions now have concrete evidence from two major American AI companies documenting systematic capability extraction by Chinese competitors.

Trust in Chinese AI benchmarks erodes. If distillation from American models contributed to Chinese labs' benchmark performance, the competitive analysis frameworks that investors and enterprises use to evaluate AI capabilities become unreliable. My prediction on Chinese AI reaching 40% global developer mindshare may need to be reassessed in light of these allegations.

API pricing and access models change. Expect all major AI providers to implement stricter rate limiting, usage pattern analysis, and identity verification for API access. The era of relatively open AI model access may be ending.

Conclusion

Anthropic's accusation against DeepSeek, Moonshot AI, and MiniMax represents a watershed moment in the AI industry's relationship with intellectual property, national security, and international competition. The 16 million-query extraction campaign is not a gray area — it is systematic capability theft at industrial scale, conducted through fraudulent accounts and designed to circumvent legitimate competitive dynamics.

The question is no longer whether AI model distillation is happening across borders. It is whether the industry and policymakers can develop effective countermeasures before the next generation of capabilities is similarly extracted.

Sources