Ai Engineering 2 min read

Anthropic Names DeepSeek, Moonshot, and MiniMax in Industrial-Scale Claude Distillation Campaigns

Anthropic's September threat intelligence report details seven harm areas including industrial-scale distillation campaigns by DeepSeek, Moonshot AI, and MiniMax using roughly 24,000 fraudulent accounts to extract capabilities from over 16 million Claude exchanges.

Anthropic published its September threat intelligence report on September 10, documenting case studies of Claude misuse disrupted between December 2025 and August 2026 across seven areas of harm: cyber operations, influence operations, surveillance, bioweapons assistance, scams, and what may be the most consequential section, illicit distillation. In a dedicated report, the company names DeepSeek, Moonshot AI, and MiniMax as running industrial-scale campaigns that used roughly 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude, extracting its capabilities in violation of Anthropic’s terms.

The Evidence Stack Has Grown Teeth

What makes this round different from previous distillation accusations (including Grok’s alleged reliance on OpenAI outputs and the contested Kimi K3 claims) is external corroboration. A CISA advisory (AA26-251A) independently corroborates that Alibaba, Moonshot AI, MiniMax, Stepfun, and Z.AI conducted industrial-scale distillation, moving the claim from vendor allegation to government assessment. Reuters separately reported Alibaba’s June extraction of Claude capabilities for the Qwen family. The supply side is documented too: a gray market of overseas API proxies known as “transfer stations” sells Claude access in China at 70-90% below official prices, the pipeline Anthropic says has pushed its distillation defense “to the dark web.”

Why Every Lab Should Read the Whole Report

The distillation section is one of seven harm areas. The report also documents a Chinese state-linked actor integrating Claude across 12 of 14 MITRE ATT&CK tactics in a nine-month campaign against Vietnamese targets, plus Russian espionage and dissident-monitoring operations. For API providers, the report is effectively a free threat-model: fake-account farming at 24,000-account scale, usage-pattern evasion, and proxy-network laundering are the attack patterns to detect, and Anthropic’s detection write-ups explain how they caught them. For policymakers weighing the G20’s light-touch principles against enforcement models, a CISA-backed advisory about foreign labs extracting a US frontier model is exactly the kind of national-security framing that tends to move legislation.

Get Insanely Good at AI

Get Insanely Good at AI

The book for developers who want to understand how AI actually works. LLMs, prompt engineering, RAG, AI agents, and production systems.

Keep Reading