On February 23, 2026, Anthropic became the first US frontier lab to publicly accuse specific Chinese AI companies of industrial-scale distillation โ naming DeepSeek, Moonshot AI, and MiniMax in an official blog post that detailed 24,000 fraudulent accounts and 16 million exchanges used to extract Claude’s capabilities. The accusations landed with a purpose: Anthropic explicitly tied the Chinese AI distillation attacks on Claude to the Congressional debate over AI chip export controls.
And Anthropic was not even the first to make the move. The disclosure came just eleven days after OpenAI sent its own Congressional memo accusing DeepSeek of the same thing. Three US frontier labs, three distillation disclosures, one policy argument. The numbers are real. So is the timing.
24,000 Fake Accounts and 16 Million Exchanges
Anthropic does not sell commercial Claude access in China. The three labs bypassed this restriction through commercial proxy services reselling API access, building what Anthropic calls “hydra cluster” architectures โ sprawling proxy networks managing over 20,000 simultaneous fake accounts that mixed distillation traffic with legitimate requests to dodge detection.
The operation’s scale was staggering. Across roughly 24,000 fraudulent accounts, the three labs generated more than 16 million total exchanges with Claude. The traffic concentrated on Claude’s most commercially valuable capabilities: agentic reasoning, coding, tool use, and computer vision. Prompt structures were highly repetitive and designed to elicit training-quality data โ not casual queries, but systematic extraction.
Anthropic’s detection signals included synchronized traffic across coordinated accounts, shared payment methods, and massive volume in narrow capability areas. Jacob Klein, Anthropic’s head of threat intelligence, told Fox News Digital: “We have high confidence these labs were conducting distillation attacks at scale.” The accused include Moonshot AI’s Kimi models and MiniMax, alongside DeepSeek. As of February 24, none of the three companies have publicly responded.
The Name You Recognize Contributed Less Than 1%
Break down the 16 million exchanges and the story looks nothing like the headlines suggest. MiniMax generated over 13 million exchanges โ roughly 79% of the total volume โ focused on agentic coding and tool orchestration. Moonshot AI contributed over 3.4 million (around 21%), targeting agentic reasoning, tool use, and computer-use agent development. DeepSeek? Roughly 150,000 exchanges. Less than 1%.
Yet DeepSeek leads virtually every headline. CNBC framed the story around DeepSeek. So did most of the coverage. The reason is simple: DeepSeek is the name Congress already knows from the R1 panic in early 2025 and from OpenAI’s February 12 Congressional memo. MiniMax is a company most lawmakers have never heard of.
As @aakashgupta noted on X: “Break down the actual distribution and the picture changes.” DeepSeek’s 150,000 exchanges had a peculiar focus โ not raw capability extraction, but “censorship-safe alternatives to policy-sensitive queries.” It was studying how Claude handles content moderation, presumably to learn how to route around politically sensitive content restrictions. That focus is revealing, but it does not explain why DeepSeek dominates the framing of a campaign MiniMax drove at 87 times the volume.

The Guardrails Argument Behind Chinese AI Distillation Attacks on Claude
Anthropic’s most consequential argument is not about intellectual property theft. It is about national security. The company warned that distilled models “lack necessary safeguards,” and that “foreign labs that distill American models can then feed these unprotected capabilities into military, intelligence, and surveillance systems โ enabling authoritarian governments to deploy frontier AI for offensive cyber operations, disinformation campaigns, and mass surveillance.”
Klein explained what makes distillation uniquely dangerous: “If you think about how you stay ahead in the AI race, compute is one piece of that. But increasingly reinforcement learning is critical. Distillation allows you to extract those capabilities.” The target is not just model weights but the RL-tuned reasoning and alignment work baked into Claude’s responses.
Gal Elbaz, CTO of cybersecurity firm Oligo Security, put it bluntly in CyberScoop’s reporting: “The scary part is, you can take all of the power and unleash it, because you don’t have anyone that actually enforces those guardrails.” A distilled Claude is Claude without Constitutional AI โ the safety framework Anthropic has built its entire brand around. DeepSeek’s specific interest in censorship-safe alternatives reinforces the point: it was not extracting capability so much as studying how to remove constraints.
Three Companies, Eleven Days, One Policy Argument
Anthropic’s disclosure did not happen in isolation. On February 12, OpenAI sent a memo to the House Select Committee on China warning that “DeepSeek’s next model should be understood in the context of its ongoing efforts to free-ride on the capabilities developed by OpenAI and other US frontier labs.” Google’s Threat Intelligence Group had published a report on February 12 documenting over 100,000 crafted prompts targeting Gemini โ the same report whose coverage resurfaced alongside Anthropic’s disclosure.
Three US frontier labs disclosed distillation campaigns within eleven days โ while Congress weighs whether to reverse the Trump administration’s January 2026 decision to clear conditional Nvidia H200 chip exports to China. Anthropic connected the dots explicitly: “distillation attacks reinforce the rationale for export controls.” Dmitri Alperovitch, CrowdStrike co-founder and chairman of the Silverado Policy Accelerator, told TechCrunch: “This should give us even more compelling reasons to refuse to sell any AI chips to any of these companies.”
The counterargument writes itself. Anthropic faces copyright lawsuits from music publishers, authors, and Reddit over training on copyrighted material. The Register noted that Anthropic “built a business by remixing content created by others.” Every major lab has used distillation internally โ the technique is not inherently illicit.
As Implicator.ai’s analysis framed it: “a trade policy argument dressed up as a security disclosure.” That framing is reductive โ the distillation is real, the scale is documented, the fraudulent accounts are not a metaphor. But the timing is also real.
Current Law Can’t Touch This โ So What Comes Next?
Existing IP law was not designed for model distillation. Fenwick’s legal analysis lays out the problem: copyright offers minimal protection because courts have generally indicated AI outputs without sufficient human input are not copyrightable, and student model weights are numerical, not expressive. The Computer Fraud and Abuse Act is no help either โ the Supreme Court’s Van Buren ruling held that CFAA does not cover authorized users who misuse data in violation of terms of service.
The strongest legal path โ breach of ToS and trade secret misappropriation โ runs into an enforcement wall. Chinese entities are practically immune to US contract claims. CSIS has recommended that Congress modernize IP protections to criminalize intentional distillation that violates ToS, designate AI firms as critical infrastructure, and consider offensive cyber operations against state-backed theft networks.
But every proposed remedy creates collateral damage. If Congress criminalizes “intentional distillation that violates ToS,” most AI model terms already prohibit competitive use of outputs. Legitimate research techniques like DistilBERT-style knowledge transfer could get caught in the same net. The question this coverage has not asked: if Congress writes distillation law broad enough to stop state-backed industrial attacks, will it also criminalize the open-source techniques that made models like DistilBERT, Mistral, and LLaMA possible?
The distillation attacks are real and documented โ but those 24,000 fraudulent accounts were accessing Claude through proxy services that paid for that access โ generating revenue for Anthropic right up until the moment disclosure became more valuable than staying quiet. That gap between detection and disclosure tells you as much about incentives as it does about security.
The Congressional chip export control vote expected in Q2 2026 will reveal whether lawmakers cite these three coordinated disclosures as justification for reversing the January H200 export liberalization. That vote will answer whether distillation evidence functions as national security intelligence โ or as the most effective lobbying campaign the AI industry has ever run.
Get the Daily Pulse
Sharp analysis on what's actually moving in AI. No hype, no filler, no weekly digest.



