Anthropic says three AI labs used fraudulent accounts to distill Claude
Anthropic says DeepSeek, Moonshot and MiniMax generated more than 16 million Claude exchanges through about 24,000 fraudulent accounts.
Quick answer
What did Anthropic announce about distillation attacks targeting Claude?
Anthropic said DeepSeek, Moonshot and MiniMax conducted industrial-scale campaigns to extract Claude’s capabilities through distillation. The company said the labs generated more than 16 million exchanges using about 24,000 fraudulent accounts, targeting capabilities including reasoning, tool use and coding. Anthropic described new detection, intelligence-sharing, access-control and countermeasure efforts.
Key takeaways
- Anthropic said DeepSeek, Moonshot and MiniMax used fraudulent accounts and proxy services to generate more than 16 million exchanges with Claude.
- The company attributed the campaigns to the three labs using request metadata, IP correlations, infrastructure indicators and, in some cases, industry corroboration.
- Anthropic said the campaigns targeted Claude capabilities including agentic reasoning, tool use, coding, computer use and computer vision.
- The company said it is expanding detection systems, intelligence sharing, account verification and product, API and model-level countermeasures.
Anthropic reports large-scale Claude extraction campaigns
Anthropic said it identified industrial-scale campaigns by DeepSeek, Moonshot AI and MiniMax to extract Claude’s capabilities for use in their own models. The company said the laboratories generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts, violating Anthropic’s terms of service and regional access restrictions.
Anthropic described the activity as distillation, a training method in which a less capable model learns from the outputs of a stronger model. The company said distillation is widely used legitimately, including by frontier labs creating smaller versions of their own models, but can also be used to obtain capabilities from another company’s systems.
Campaign details
Anthropic said DeepSeek generated more than 150,000 exchanges focused on reasoning across tasks, rubric-based grading for reinforcement learning, and censorship-safe alternatives to policy-sensitive queries. The company said synchronized traffic, identical patterns, shared payment methods and coordinated timing indicated an effort to increase throughput and avoid detection. Anthropic also said it traced accounts to specific DeepSeek researchers through request metadata.
Moonshot AI generated more than 3.4 million exchanges, according to Anthropic. The company said the campaign targeted agentic reasoning, tool use, coding, data analysis, computer-use agent development and computer vision. Anthropic said Moonshot used hundreds of fraudulent accounts across multiple access pathways and later attempted to extract and reconstruct Claude’s reasoning traces.
MiniMax generated more than 13 million exchanges, Anthropic said, targeting agentic coding, tool use and orchestration. The company said it detected the campaign while it was active, before MiniMax released the model it was training. When Anthropic released a new model during the campaign, it said MiniMax redirected nearly half its traffic within 24 hours to capture capabilities from the latest system.
Access and defenses
Anthropic said the laboratories used commercial proxy services to access Claude at scale despite the company’s lack of commercial Claude access in China and to subsidiaries of Chinese companies outside the country. These services operated networks of fraudulent accounts across Anthropic’s API and third-party cloud platforms. In one case, Anthropic said, a proxy network managed more than 20,000 fraudulent accounts at the same time.
The company said it is investing in classifiers and behavioral-fingerprinting systems to detect distillation patterns, including chain-of-thought elicitation and coordinated activity across accounts. Anthropic also said it is sharing technical indicators with AI labs, cloud providers and authorities; strengthening verification for educational, security-research and startup accounts; and developing product, API and model safeguards to reduce illicit distillation.
Anthropic published the announcement “Detecting and preventing distillation attacks” on Feb. 23, 2026.
Frequently asked questions
- Which laboratories did Anthropic identify?
- Anthropic identified DeepSeek, Moonshot AI and MiniMax. It said each campaign was attributed with high confidence using technical indicators and related evidence.
- How large were the campaigns?
- Anthropic said DeepSeek generated more than 150,000 exchanges, Moonshot more than 3.4 million, and MiniMax more than 13 million. Together, the campaigns involved more than 16 million exchanges through approximately 24,000 fraudulent accounts.
- What capabilities were targeted?
- The company said the campaigns focused on Claude’s agentic reasoning, tool use and coding capabilities, with additional targeting of computer-use agents, computer vision, data analysis and reasoning traces.
- How is Anthropic responding?
- Anthropic said it has built classifiers and behavioral-fingerprinting systems, is sharing technical indicators, has strengthened verification for several account pathways, and is developing safeguards intended to reduce illicit distillation.