Anthropic says it identified industrial-scale campaigns by DeepSeek, Moonshot AI and MiniMax that used about 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude. Published on 23 February, the report frames the activity as illicit capability extraction rather than ordinary model evaluation. The allegations and attribution are Anthropic's; the named companies' positions were not included in the report.
Anthropic Watch analysis
What happened
Distillation itself is a normal technique: a smaller model learns from a stronger model's outputs. Anthropic's objection is about access, scale and intent. It says coordinated accounts and proxy services repeatedly targeted Claude's reasoning, coding and tool-use strengths while evading regional restrictions and its terms.
The company reports more than 150,000 exchanges associated with DeepSeek, more than 3.4 million with Moonshot and more than 13 million with MiniMax. It says its attribution drew on IP correlation, request metadata, infrastructure indicators and, in some cases, corroboration from industry partners. Anthropic also says one proxy network managed over 20,000 fraudulent accounts at once. TechCrunch reported the accusations and said it had contacted all three named companies for comment.
Why it matters
The difficult line is not whether model outputs can teach another system. Benchmarking, synthetic-data generation and vendors distilling their own models are established practices. The security question is when distributed access, concealed identity and repetitive capability-targeting become an extraction operation.
Anthropic says it is responding with traffic classifiers, behavioural fingerprinting, stronger account verification, intelligence sharing and model-level countermeasures. Those controls will need to distinguish hostile collection from legitimate researchers and customers without turning every unusual workload into a bloke in a false moustache.
Our read
This is partly a platform-security story and partly a test of what the industry can prove. Large numbers make a dramatic headline, but the durable standard should be transparent methodology, auditable attribution and a fair route for accused parties to answer.
What to watch
- Whether DeepSeek, Moonshot AI or MiniMax publicly contest Anthropic's attribution.
- How providers define permitted evaluation and prohibited extraction in practice.
- Whether countermeasures create false positives for security research or high-volume customers.
- What technical evidence can be shared without teaching attackers how to evade detection.
Discussion spark: Where should the line sit between legitimate learning from model outputs, competitive benchmarking and theft of proprietary capability?
Sources and evidence
- Detecting and preventing distillation attacks (23 February 2026, 00:00 UTC)
- Anthropic accuses Chinese AI labs of mining Claude as US debates AI chip exports (23 February 2026, 19:57 UTC)
Anthropic Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by Anthropic.