The AI race just turned into something darker. Anthropic has publicly accused three major Chinese AI labs of running an industrial-scale operation to secretly steal capabilities from its Claude model — and the numbers behind it are staggering.
Table of Contents

The Distillation Attack: What Happened
| Detail | Info |
|---|---|
| Accused Companies | DeepSeek, Moonshot AI, MiniMax |
| Method | “Distillation attacks” via fake accounts |
| Fraudulent Accounts Created | ~24,000 |
| Total Exchanges with Claude | 16+ million |
| DeepSeek’s Target | Reasoning, censorship-safe query alternatives |
| Moonshot AI’s Target | Agentic reasoning, tool use, coding |
| MiniMax’s Target | Agentic coding, tool use, orchestration |
| Anthropic’s Valuation | $380 billion (post $30B Series G) |
How the Operation Actually Worked
Since Claude is not available commercially in China for national security reasons, the labs used commercial proxy services running “hydra cluster” architectures — sprawling networks of fraudulent accounts distributing traffic across Anthropic’s API and third-party cloud platforms.
In one case, a single proxy network managed more than 20,000 fraudulent accounts simultaneously, mixing distillation traffic with unrelated customer requests to make detection harder.
Once access was secured, the labs generated carefully crafted prompts designed to extract specific capabilities — with DeepSeek alone running synchronised traffic across accounts using identical patterns and coordinated timing to load-balance requests and avoid detection. Notably, Anthropic detected MiniMax’s campaign while it was still active — before MiniMax had even released the model it was training.

The Bigger Picture — And the Uncomfortable Irony
Anthropic isn’t just calling out three companies. It’s explicitly using this disclosure to push for tighter US chip export controls on China. The company argues that distillation attacks at this scale require access to advanced chips, and that restricting chip exports limits both direct model training and the scale of illicit distillation.
Anthropic warned that illicitly distilled models likely lack safety guardrails, potentially enabling authoritarian governments to deploy frontier AI for offensive cyber operations, disinformation campaigns, and mass surveillance. Critics, however, were quick to note the irony — Anthropic itself faces active lawsuits from authors accusing it of downloading books in bulk from shadow libraries to train its own models without permission.
For Anthropic’s full technical report, see their official blog post. Also check our coverage of DeepSeek vs Claude benchmarks and US-China AI chip export controls explained on TechnoSports.
FAQs
Is model distillation itself illegal?
No — it’s a standard industry technique, but using it on a competitor’s model without permission violates terms of service.
Has Anthropic filed lawsuits against DeepSeek, Moonshot, or MiniMax?
Not yet — Anthropic has cut off access and is urging coordinated industry and policy action instead.





