# Anthropic Names DeepSeek, Moonshot, MiniMax — Distillation as a Query-Budget War

Times of AI Desk · 2026-02-23 · Security

[https://timesof.ai/2026/02/anthropic-detecting-preventing-distillation-attacks](https://timesof.ai/2026/02/anthropic-detecting-preventing-distillation-attacks)

> Anthropic (Feb 23) alleged DeepSeek, Moonshot, and MiniMax ran industrial Claude distillation via ~24,000 fraudulent accounts and 16M+ exchanges—ToS and China regional-access violations. Most granular multi-lab extraction report that month, eleven days after OpenAI’s House DeepSeek memo.

Frontier labs spent billions on training and safety; distillation turns that investment into a **query-budget problem**. Anthropic’s proprietary move: **name three Chinese labs with concrete operational metrics**—not a vague “adversarial activity” note—so cloud providers and policymakers treat model-output abuse as strategic security, not spam moderation.

**Anthropic** published “Detecting and preventing distillation attacks” on February 23. Named labs: **DeepSeek**, **Moonshot**, **MiniMax**. Method: industrial-scale **distillation**—training weaker models on Claude outputs. Scale claimed: ~**24,000** fraudulent accounts; **>16 million** exchanges combined. Violations claimed: ToS forbidding surreptitious harvesting; **China regional access restrictions** (Claude not authorized for use in China under Anthropic’s rules). Risk framing: distillation can strip or bypass **safety guardrails** (weapons, mass surveillance)—national-security concern beyond IP theft. Defenses: detection/prevention investment (behavioral fingerprinting, account integrity, monitoring). NYT same-day: Anthropic blog as source of account/volume figures; distillation common in research but prohibited under Anthropic commercial terms at this covert scale.

| Date | Actor | Signal |
|------|--------|--------|
| Feb 12 | OpenAI | Memo to House China committee on DeepSeek distillation tactics |
| Feb 12 | Google Threat Intelligence (cited) | Distillation / adversarial AI tracker notes |
| **Feb 23** | **Anthropic** | **Named three labs; 24k accounts; 16M+ exchanges** |

## Claims vs checks

Account counts, exchange volumes, and lab names are **Anthropic-asserted** (primary post); NYT relays them. Named labs’ responses—if any—are not independently adjudicated here. Treat as a **lab security disclosure**, not a court finding.

## Limits

- Figures are Anthropic operational telemetry, not a third-party forensic audit.
- Distillation vs legitimate research use is a ToS/regional-policy line; jurisdictions differ.
- Defenses described qualitatively—efficacy not independently scored.

## Sources

- Anthropic: [“Detecting and preventing distillation attacks”](https://anthropic.com/news/detecting-and-preventing-distillation-attacks) (February 23, 2026). Primary.
- The New York Times: Anthropic accuses three Chinese companies of harvesting Claude data (February 23, 2026).
- Prior context: OpenAI House committee memo (February 12, 2026).
