Discussion

Anthropic says distillation campaigns mined 16 million Claude exchanges

In Model Chat

Anthropic Watch
Anthropic WatchParticipantOpening post
#1936

Anthropic says it identified industrial-scale campaigns by DeepSeek, Moonshot AI and MiniMax that used about 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude. Published on 23 February, the report frames the activity as illicit capability extraction rather than ordinary model evaluation. The allegations and attribution are Anthropic's; the named companies' positions were not included in the report.

Anthropic Watch analysis

What happened

Distillation itself is a normal technique: a smaller model learns from a stronger model's outputs. Anthropic's objection is about access, scale and intent. It says coordinated accounts and proxy services repeatedly targeted Claude's reasoning, coding and tool-use strengths while evading regional restrictions and its terms.

The company reports more than 150,000 exchanges associated with DeepSeek, more than 3.4 million with Moonshot and more than 13 million with MiniMax. It says its attribution drew on IP correlation, request metadata, infrastructure indicators and, in some cases, corroboration from industry partners. Anthropic also says one proxy network managed over 20,000 fraudulent accounts at once. TechCrunch reported the accusations and said it had contacted all three named companies for comment.

Why it matters

The difficult line is not whether model outputs can teach another system. Benchmarking, synthetic-data generation and vendors distilling their own models are established practices. The security question is when distributed access, concealed identity and repetitive capability-targeting become an extraction operation.

Anthropic says it is responding with traffic classifiers, behavioural fingerprinting, stronger account verification, intelligence sharing and model-level countermeasures. Those controls will need to distinguish hostile collection from legitimate researchers and customers without turning every unusual workload into a bloke in a false moustache.

Our read

This is partly a platform-security story and partly a test of what the industry can prove. Large numbers make a dramatic headline, but the durable standard should be transparent methodology, auditable attribution and a fair route for accused parties to answer.

What to watch

  • Whether DeepSeek, Moonshot AI or MiniMax publicly contest Anthropic's attribution.
  • How providers define permitted evaluation and prohibited extraction in practice.
  • Whether countermeasures create false positives for security research or high-volume customers.
  • What technical evidence can be shared without teaching attackers how to evade detection.

Discussion spark: Where should the line sit between legitimate learning from model outputs, competitive benchmarking and theft of proprietary capability?

Sources and evidence

Anthropic Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by Anthropic.