Anthropic has disclosed that three AI laboratories DeepSeek, Moonshot AI and MiniMax ran industrial-scale campaigns to illicitly extract capabilities from its Claude models using a technique known as distillation. The company says the labs generated more than 16 million exchanges through roughly 24,000 fraudulent accounts, violating its terms of service and regional access restrictions. Distillation, a standard method for training smaller models on the outputs of larger ones, was allegedly repurposed here to copy Claude’s strengths in areas such as reasoning, tool use and coding at a fraction of the time and cost of independent development.
Anthropic warns that models built through such illicit distillation are unlikely to retain the safeguards embedded in the original systems, heightening national security risks. It argues that stripped-down models could be used by state and non-state actors to support bioweapons development, offensive cyber operations, disinformation and mass surveillance, particularly if these systems are integrated into military or intelligence infrastructures or released as open source. The company links these campaigns to foreign laboratories, including entities subject to the control of the Chinese Communist Party, and says the attacks threaten to erode the effectiveness of US export controls designed to protect America’s AI lead.
According to Anthropic, DeepSeek’s campaign of more than 150,000 exchanges targeted Claude’s reasoning abilities, reinforcement learning-style grading and censorship-safe responses, including prompts to elicit internal chain-of-thought. Moonshot AI conducted over 3.4 million exchanges focused on agentic reasoning, tool use, coding, data analysis, computer-use agents and vision, later shifting toward reconstructing Claude’s reasoning traces. MiniMax generated more than 13 million exchanges aimed at agentic coding and tool orchestration, and reportedly pivoted within 24 hours to a newly released Claude model during an active campaign.
Anthropic says these operations relied on commercial proxy services and “hydra cluster” architectures that manage sprawling networks of fraudulent accounts to resell access to frontier models and evade regional restrictions. The company has responded with new detection classifiers, behavioral fingerprinting, stricter access controls and technical countermeasures intended to reduce the usefulness of its outputs for training rival systems. It is also sharing indicators with other AI labs, cloud providers and authorities, and is calling for coordinated industry and policy action to contain distillation attacks as their scale and sophistication increase.

