You invest billions for years, with hundreds of the brightest minds working day and night. And then you discover that someone has been quietly, systematically, and on a massive scale reaping the fruits of your labor without paying a single cent. That is exactly what happened to the American company Anthropic.
The Anatomy of the Theft, Step by Step
Anthropic published a report that shook the technology world. The company revealed that three Chinese AI labs—specifically DeepSeek, Moonshot AI, and MiniMax—conducted coordinated industrial espionage campaigns against its Claude chatbot. They used a technique known as "distillation" and generated more than 16 million interactions through approximately 24,000 fraudulent accounts.
Distillation itself is not illegal. It is a common method in which a less capable model is trained on the outputs of a more powerful one. Companies use it themselves to create cheaper, more compact versions of their own systems. The problem arises when you apply it to someone else's model without permission, on a massive scale, with the goal of stealing years of research at a fraction of the cost.
The Chinese labs could not simply purchase access to Claude because Anthropic does not provide commercial access in China. So what did they do? They used commercial proxy services that resell access to American AI models. They built networks of fraudulent accounts using what Anthropic calls "hydra cluster" architectures. When one account is blocked, another immediately replaces it. In one case, a single proxy network managed more than 20,000 fake accounts at once.
Each of the Three Labs Had Its Own Style
DeepSeek generated more than 150,000 interactions. It synchronized traffic across accounts, shared payment methods, and coordinated timing to increase throughput and evade detection. Interestingly, its prompts asked Claude to "imagine and describe the internal reasoning behind a completed answer" step by step. In other words, it generated chain-of-thought training data at scale. It also had Claude create "censorship-safe" alternatives to politically sensitive queries, such as questions about dissidents or authoritarianism. Presumably, this was intended to train its own models to avoid such topics.
Moonshot AI went even further, generating more than 3.4 million interactions. It used hundreds of fraudulent accounts across various access channels to make the campaign appear less coordinated. Anthropic nevertheless detected it through request metadata that matched the public profiles of senior Moonshot employees.
The record holder was MiniMax, with more than 13 million interactions. And here comes the chilling detail: Anthropic detected the campaign before MiniMax had even released the model it was training. This gave Anthropic an unprecedented view of the entire lifecycle of a distillation attack. When Anthropic released a new model in the middle of the campaign, MiniMax redirected nearly half of its traffic within 24 hours to capture the capabilities of the latest system.
More Than Just Intellectual Property Theft
It might seem that this is "just" technology theft. But Anthropic warns of far more serious consequences. Models built through illegal distillation are unlikely to retain the safety guardrails that American companies painstakingly develop. These guardrails prevent AI from being misused to develop biological weapons or launch cyberattacks.
Foreign labs could then integrate these "unlocked" capabilities into military, intelligence, and surveillance systems. Authoritarian governments could deploy cutting-edge AI for offensive cyber operations or mass surveillance of their populations. Moreover, if such models are released as open source, the risk spreads like an avalanche, without any oversight.
Export Controls Are Not Enough. What Now?
Washington has tried to slow China's AI progress by restricting access to the most advanced chips. But distillation attacks circumvent this strategy. Jacob Klein, Anthropic's head of threat intelligence, explained it clearly: "If you're thinking about how to stay ahead in the AI race, compute is one part. But reinforcement through feedback is increasingly critical. Distillation allows you to extract these capabilities."
Anthropic is sharing technical indicators with other AI labs, cloud providers, and relevant authorities. It is strengthening verification for educational accounts and research programs, which attackers exploit most often. It is also developing countermeasures at the product, API, and model levels.
This is not an isolated allegation. On February 12, OpenAI informed the House Select Committee on the Chinese Communist Party that DeepSeek had systematically "stolen" its intellectual property. Google's Threat Intelligence Group warned of campaigns involving more than 100,000 prompts aimed at replicating the capabilities of the Gemini model.
Distillation attacks have become a new battleground in the technology war between the United States and China. And as Klein aptly noted: "There is no immediate silver bullet." The solution requires coordination across the entire industry, cloud providers, and policymakers. Anthropic cannot handle it alone. And frankly, neither can anyone else.
Sources: aol.com and yahoo.com



