Skip to content
GOPPO

News · AI summarised to understand what matters

Back to news

Security & Ethics

Published on

Anthropic says three Chinese AI labs ran large-scale distillation campaign against Claude

Anthropic alleges that three Chinese AI labs used around 24,000 fraudulent accounts and more than 16 million prompts to “distill” capabilities from its Claude chatbot and improve rival models.

  • ai-safety,model-security,china,distillation,geopolitics

Summary

Anthropic alleges that Chinese AI labs DeepSeek, Moonshot AI and MiniMax ran industrial‑scale “distillation” campaigns against its Claude chatbot using roughly 24,000 fraudulent accounts and over 16 million interactions. The company frames the incident as a security concern, warning that advanced capabilities can be reused without the original safety guardrails.

In practice

Anthropic says it detected the campaigns using IP address correlations, request metadata and infrastructure patterns that differed from normal customer traffic. The actors allegedly targeted Claude’s most advanced skills, such as complex reasoning, coding and tool use, rather than the casual queries typical of everyday users.

The technique they are accused of using is distillation, where a weaker model is trained on the outputs of a stronger one, a standard practice inside AI labs but in this case allegedly carried out without authorization. Anthropic claims the three labs violated its terms of service and regional access rules by relying on fraudulent accounts and proxy services to query Claude at scale.

The company says it has shared its findings with relevant U.S. government bodies and industry partners. By publicly naming the labs, Anthropic hopes to prompt more structured government action or engagement with the companies involved.

Context

The disclosure comes amid mounting warnings across the U.S. AI sector about distillation by foreign rivals. OpenAI has told U.S. lawmakers that DeepSeek is using increasingly sophisticated distillation methods to free‑ride on capabilities developed by OpenAI and other frontier labs.

On the same day as Anthropic’s announcement, Google’s Threat Intelligence Group reported seeing distillation attacks against its Gemini models involving more than 100,000 prompts aimed at cloning the system’s reasoning abilities. Google linked this activity to private‑sector companies and state‑aligned actors.

Industry voices describe these incidents as early warnings of a broader wave of similar attacks as more organizations build their own large language models. The central worry is that such campaigns allow competitors to shortcut years of investment and safety work by extracting capabilities directly from leading systems.

Why it matters

  • Highlights that commercial AI chatbots can be systematically abused to train competing models at industrial scale.
  • Raises security concerns that copied capabilities may be reused without the original safety guardrails.
  • Increases pressure on governments to set clearer rules around access, export controls and protection for frontier AI models.
  • Signals that any company deploying advanced models may need stronger monitoring and defenses against distillation attacks.