Anthropic alleges that three China-based AI labs used about 24,000 fake accounts to generate more than 16 million interactions with its Claude model in a coordinated distillation campaign designed to extract high-value outputs. The company says it detected the effort via IP correlations, request metadata and unusual infrastructure signals and has shared its findings with U.S. government agencies. Anthropic warns distilled models may lack the safety guardrails of frontier systems and could be repurposed for military, intelligence or surveillance uses. Similar warnings from OpenAI and Google suggest distillation is an emerging flashpoint in the U.S.–China AI rivalry.
Anthropic Alleges 24,000 Fake Accounts Harvested Claude in Coordinated 'Distillation' Campaign — 16M+ Queries Reported

Anthropic, a leading U.S. AI company, alleges that three China-based laboratories — DeepSeek, Moonshot AI and MiniMax — used roughly 24,000 fraudulent accounts to run more than 16 million interactions with Anthropic’s Claude chatbot in a coordinated "distillation" campaign. The company told reporters it first identified the activity after analyzing traffic patterns and related infrastructure indicators in a report first obtained by Fox News Digital.
What Anthropic alleges
According to Anthropic, the campaigns targeted Claude’s most advanced capabilities — complex reasoning, coding and tool use — rather than simple consumer prompts. The company says this activity appears aimed at extracting high-value outputs that could be used to train competing models.
How the activity was detected
Anthropic says its investigators identified the campaigns by correlating IP addresses, reviewing request metadata and spotting infrastructure signals that differed substantially from normal customer traffic. Jacob Klein, Anthropic’s head of threat intelligence, told reporters the company has "high confidence these labs were conducting distillation attacks at scale."
What distillation means and why it matters
Distillation is a standard technique in AI development where a smaller or cheaper model is trained on the outputs of a stronger model. While distillation is often used legitimately to create efficient variants of a lab’s own systems, Anthropic says these campaigns were unauthorized and designed to shortcut extensive reinforcement learning and safety work.
"We have high confidence these labs were conducting distillation attacks at scale," Jacob Klein said. "There isn’t an immediate silver bullet to stop all of these. We view this as larger than Anthropic."
Security and policy implications
Anthropic warns that models derived from large-scale, unauthorized distillation may not retain the safety guardrails built into frontier systems. The company argues such weakened models could be repurposed for military, intelligence, cyberoffensive, disinformation and mass surveillance uses if adopted by hostile actors.
Anthropic has shared its findings with relevant U.S. government agencies and industry partners, and it says it reached out to the named labs for comment but had not received replies. The company also noted it has found no public evidence of direct coordination by the Chinese government, while acknowledging proxy services that resell access to U.S. frontier models operate openly in China.
Related reports from other companies
The allegation follows similar warnings: OpenAI told a U.S. congressional committee that DeepSeek allegedly harvested outputs from ChatGPT using masking techniques, and Google’s Threat Intelligence Group reported "distillation attacks" against its Gemini models involving large prompt sets. Together, the reports highlight distillation as a growing concern in the U.S.–China AI competition.
Broader context
Experts note that export controls on advanced chips and model weights focus on one layer of competitive advantage. Anthropic stresses that reinforcement learning and the refinement of model behavior are increasingly important, and that distillation can allow competitors to capture those post-training capabilities without direct chip transfers.
Next steps
Anthropic says it is continuing to investigate, has informed government partners, and believes public naming could prompt further engagement or policy responses. The company also flagged tensions with the U.S. Department of Defense over permissible military uses of Claude, underscoring the complex mix of commercial, national-security and ethical issues around frontier AI.
Help us improve.




























