Anthropic reveals DeepSeek, Moonshot, and MiniMax ran industrial-scale distillation attacks using 24,000 fake accounts to steal Claude AI capabilities. (Read MoreAnthropic reveals DeepSeek, Moonshot, and MiniMax ran industrial-scale distillation attacks using 24,000 fake accounts to steal Claude AI capabilities. (Read More

Anthropic Exposes 16M Query Theft Campaign by Chinese AI Labs

2026/02/24 02:32
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Anthropic Exposes 16M Query Theft Campaign by Chinese AI Labs

Tony Kim Feb 23, 2026 18:32

Anthropic reveals DeepSeek, Moonshot, and MiniMax ran industrial-scale distillation attacks using 24,000 fake accounts to steal Claude AI capabilities.

Anthropic Exposes 16M Query Theft Campaign by Chinese AI Labs

Anthropic dropped a bombshell Tuesday, publicly naming three Chinese AI laboratories—DeepSeek, Moonshot, and MiniMax—as perpetrators of coordinated campaigns to steal Claude's capabilities through over 16 million fraudulent API exchanges.

The attacks used approximately 24,000 fake accounts to circumvent Anthropic's regional access restrictions and terms of service. One proxy network alone managed more than 20,000 simultaneous fraudulent accounts, mixing distillation traffic with legitimate requests to evade detection.

The Numbers Tell the Story

MiniMax led the assault with 13 million exchanges targeting agentic coding and tool orchestration. Moonshot followed with 3.4 million exchanges focused on computer-use agent development and reasoning capabilities. DeepSeek's campaign, while smaller at 150,000 exchanges, employed particularly sophisticated techniques—including prompts designed to make Claude articulate its internal reasoning step-by-step, essentially generating chain-of-thought training data on demand.

Anthropic traced several DeepSeek accounts directly to specific researchers at the lab through request metadata analysis.

Why This Matters Beyond Corporate Espionage

The timing here isn't coincidental. OpenAI publicly accused DeepSeek of distilling ChatGPT just three days earlier on February 21. Google's Threat Intelligence Group flagged increased distillation activity on February 16, including a campaign using over 100,000 prompts to replicate Gemini's reasoning abilities.

What makes this particularly concerning? Anthropic argues these attacks undermine U.S. export controls on advanced chips. Foreign labs can effectively bypass innovation requirements by extracting capabilities from American models—and they need those restricted chips to run distillation at scale anyway.

"Illicitly distilled models lack necessary safeguards," Anthropic warned, noting stripped-out protections could enable "offensive cyber operations, disinformation campaigns, and mass surveillance" by authoritarian governments.

The Hydra Problem

Anthropic described the infrastructure enabling these attacks as "hydra cluster" architectures—sprawling networks with no single point of failure. Ban one account, another spawns immediately. The proxy services reselling Claude access made detection exponentially harder by distributing traffic across Anthropic's API and third-party cloud platforms simultaneously.

When Anthropic released a new Claude model during MiniMax's active campaign, the lab pivoted within 24 hours, redirecting nearly half their traffic to capture the latest capabilities. That kind of operational agility suggests these aren't opportunistic attacks but sustained, well-resourced operations.

Anthropic's Countermeasures

The company outlined several defensive measures: behavioral fingerprinting systems to detect distillation patterns, strengthened verification for educational and startup accounts (the most commonly exploited pathways), and model-level safeguards designed to degrade output quality for illicit extraction without affecting legitimate users.

Anthropic is sharing technical indicators with other AI labs, cloud providers, and government authorities. The message is clear: this requires industry-wide coordination.

For investors tracking AI infrastructure plays, this escalation adds another variable to the competitive landscape. Labs that can't defend their models risk watching their R&D investments walk out the door—16 million queries at a time.

Image source: Shutterstock
  • ai security
  • anthropic
  • deepseek
  • distillation attacks
  • china tech
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Silver Prices Edge Closer to a Pivotal Support and Resistance Test

Silver Prices Edge Closer to a Pivotal Support and Resistance Test

The post Silver Prices Edge Closer to a Pivotal Support and Resistance Test appeared on BitcoinEthereumNews.com. The silver market, although experiencing recent
Share
BitcoinEthereumNews2026/03/07 11:29
U.S. Court Finds Pastor Found Guilty in $3M Crypto Scam

U.S. Court Finds Pastor Found Guilty in $3M Crypto Scam

The post U.S. Court Finds Pastor Found Guilty in $3M Crypto Scam appeared on BitcoinEthereumNews.com. Crime 18 September 2025 | 04:05 A Colorado judge has brought closure to one of the state’s most unusual cryptocurrency scandals, declaring INDXcoin to be a fraudulent operation and ordering its founders, Denver pastor Eli Regalado and his wife Kaitlyn, to repay $3.34 million. The ruling, issued by District Court Judge Heidi L. Kutcher, came nearly two years after the couple persuaded hundreds of people to invest in their token, promising safety and abundance through a Christian-branded platform called the Kingdom Wealth Exchange. The scheme ran between June 2022 and April 2023 and drew in more than 300 participants, many of them members of local church networks. Marketing materials portrayed INDXcoin as a low-risk gateway to prosperity, yet the project unraveled almost immediately. The exchange itself collapsed within 24 hours of launch, wiping out investors’ money. Despite this failure—and despite an auditor’s damning review that gave the system a “0 out of 10” for security—the Regalados kept presenting it as a solid opportunity. Colorado regulators argued that the couple’s faith-based appeal was central to the fraud. Securities Commissioner Tung Chan said the Regalados “dressed an old scam in new technology” and used their standing within the Christian community to convince people who had little knowledge of crypto. For him, the case illustrates how modern digital assets can be exploited to replicate classic Ponzi-style tactics under a different name. Court filings revealed where much of the money ended up: luxury goods, vacations, jewelry, a Range Rover, high-end clothing, and even dental procedures. In a video that drew worldwide attention earlier this year, Eli Regalado admitted the funds had been spent, explaining that a portion went to taxes while the remainder was used for a home renovation he claimed was divinely inspired. The judgment not only confirms that INDXcoin qualifies as a…
Share
BitcoinEthereumNews2025/09/18 09:14
[Newspoint] Overpaid troll

[Newspoint] Overpaid troll

KAUFMAN. Former president Rodrigo Duterte's lawyer Nicholas Kaufman delivers his opening statement before the ICC Pre-Trial Chamber I on February 23, 2026.
Share
Rappler2026/03/07 11:00