Anthropic Names DeepSeek, Moonshot, MiniMax — Distillation as a Query-Budget War
Anthropic (Feb 23) alleged DeepSeek, Moonshot, and MiniMax ran industrial Claude distillation via ~24,000 fraudulent accounts and 16M+ exchanges—ToS and China regional-access violations. Most granular multi-lab extraction report that month, eleven days after OpenAI’s House DeepSeek memo.

Frontier labs spent billions on training and safety; distillation turns that investment into a query-budget problem. Anthropic’s proprietary move: name three Chinese labs with concrete operational metrics—not a vague “adversarial activity” note—so cloud providers and policymakers treat model-output abuse as strategic security, not spam moderation.
Anthropic published “Detecting and preventing distillation attacks” on February 23. Named labs: DeepSeek, Moonshot, MiniMax. Method: industrial-scale distillation—training weaker models on Claude outputs. Scale claimed: ~24,000 fraudulent accounts; >16 million exchanges combined. Violations claimed: ToS forbidding surreptitious harvesting; China regional access restrictions (Claude not authorized for use in China under Anthropic’s rules). Risk framing: distillation can strip or bypass safety guardrails (weapons, mass surveillance)—national-security concern beyond IP theft. Defenses: detection/prevention investment (behavioral fingerprinting, account integrity, monitoring). NYT same-day: Anthropic blog as source of account/volume figures; distillation common in research but prohibited under Anthropic commercial terms at this covert scale.
| Date | Actor | Signal |
|---|---|---|
| Feb 12 | OpenAI | Memo to House China committee on DeepSeek distillation tactics |
| Feb 12 | Google Threat Intelligence (cited) | Distillation / adversarial AI tracker notes |
| Feb 23 | Anthropic | Named three labs; 24k accounts; 16M+ exchanges |
Claims vs checks
Account counts, exchange volumes, and lab names are Anthropic-asserted (primary post); NYT relays them. Named labs’ responses—if any—are not independently adjudicated here. Treat as a lab security disclosure, not a court finding.
Limits
- Figures are Anthropic operational telemetry, not a third-party forensic audit.
- Distillation vs legitimate research use is a ToS/regional-policy line; jurisdictions differ.
- Defenses described qualitatively—efficacy not independently scored.
Sources
- Anthropic: “Detecting and preventing distillation attacks” (February 23, 2026). Primary.
- The New York Times: Anthropic accuses three Chinese companies of harvesting Claude data (February 23, 2026).
- Prior context: OpenAI House committee memo (February 12, 2026).