Friday, Oct 9 | --:--
Back to home

Anthropic Names DeepSeek, Moonshot, MiniMax — Distillation as a Query-Budget War

Anthropic (Feb 23) alleged DeepSeek, Moonshot, and MiniMax ran industrial Claude distillation via ~24,000 fraudulent accounts and 16M+ exchanges—ToS and China regional-access violations. Most granular multi-lab extraction report that month, eleven days after OpenAI’s House DeepSeek memo.

Times of AI Desk 5 min read San Francisco, CA View as Markdown
Cover illustration for Anthropic Names DeepSeek, Moonshot, MiniMax — Distillation as a Query-Budget War

Frontier labs spent billions on training and safety; distillation turns that investment into a query-budget problem. Anthropic’s proprietary move: name three Chinese labs with concrete operational metrics—not a vague “adversarial activity” note—so cloud providers and policymakers treat model-output abuse as strategic security, not spam moderation.

Anthropic published “Detecting and preventing distillation attacks” on February 23. Named labs: DeepSeek, Moonshot, MiniMax. Method: industrial-scale distillation—training weaker models on Claude outputs. Scale claimed: ~24,000 fraudulent accounts; >16 million exchanges combined. Violations claimed: ToS forbidding surreptitious harvesting; China regional access restrictions (Claude not authorized for use in China under Anthropic’s rules). Risk framing: distillation can strip or bypass safety guardrails (weapons, mass surveillance)—national-security concern beyond IP theft. Defenses: detection/prevention investment (behavioral fingerprinting, account integrity, monitoring). NYT same-day: Anthropic blog as source of account/volume figures; distillation common in research but prohibited under Anthropic commercial terms at this covert scale.

Date Actor Signal
Feb 12 OpenAI Memo to House China committee on DeepSeek distillation tactics
Feb 12 Google Threat Intelligence (cited) Distillation / adversarial AI tracker notes
Feb 23 Anthropic Named three labs; 24k accounts; 16M+ exchanges

Claims vs checks

Account counts, exchange volumes, and lab names are Anthropic-asserted (primary post); NYT relays them. Named labs’ responses—if any—are not independently adjudicated here. Treat as a lab security disclosure, not a court finding.

Limits

  • Figures are Anthropic operational telemetry, not a third-party forensic audit.
  • Distillation vs legitimate research use is a ToS/regional-policy line; jurisdictions differ.
  • Defenses described qualitatively—efficacy not independently scored.

Sources

  • Anthropic: “Detecting and preventing distillation attacks” (February 23, 2026). Primary.
  • The New York Times: Anthropic accuses three Chinese companies of harvesting Claude data (February 23, 2026).
  • Prior context: OpenAI House committee memo (February 12, 2026).

Prior Coverage

Earlier Times of AI reporting on this thread.

Scroll to continue reading