Timeline

Anthropic accuses DeepSeek, Moonshot and MiniMax of industrial-scale distillation attacks

MiniMax accounted for over 13 million of the exchanges, Moonshot 3.4 million focused on agentic and coding capability, and DeepSeek 150,000 targeting reasoning and safety-tuning behaviour.

  • Security & misuse
  • Open weights & ecosystem
  • Major

Anthropic said it had identified and disrupted coordinated campaigns by three Chinese AI companies — DeepSeek, Moonshot AI and MiniMax — to extract Claude’s capabilities through distillation, the practice of training a new model on a stronger model’s outputs. The company said it traced roughly 24,000 fraudulent accounts, distributed across APIs and cloud platforms in what it called “hydra cluster” architectures, generating more than 16 million exchanges with Claude in violation of its terms of service and regional access restrictions.

Anthropic broke the activity down by company. MiniMax accounted for the largest volume, over 13 million exchanges concentrated on agentic coding and tool orchestration, and the company said MiniMax’s operators pivoted their prompting strategy within 24 hours of a new Claude model release. Moonshot AI generated over 3.4 million exchanges focused on agentic reasoning, tool use, coding and computer vision. DeepSeek’s activity was smaller by volume, over 150,000 exchanges, but Anthropic said it targeted reasoning traces, reward-model construction and ways to elicit answers Claude would normally decline on censorship-adjacent queries, using synchronised traffic and shared payment methods across accounts.

Anthropic said it responded with new detection classifiers, behavioural fingerprinting and tightened access controls, and that it was sharing technical indicators with industry partners and authorities, arguing “no company can solve this alone.” The company framed the campaigns as undermining the intent of US export controls: capabilities extracted this way, it argued, arrive without the safety tuning built into the original model, and could let labs facing chip restrictions reach frontier-adjacent capability without matching the safeguards. None of the three accused companies had issued a public response noted in Anthropic’s post. The episode fed a wider, unresolved argument over whether such distillation constitutes IP theft or ordinary competitive benchmarking against a public API — a dispute that recurred months later when a White House official separately accused Moonshot of distilling a different Anthropic model to build its Kimi K3 release.