Key facts
- Anthropic claims Chinese AI firms used fake accounts and stolen credit cards to access Claude.
- Moonshot AI and DeepSeek allegedly used "transfer stations" to send user queries to Claude.
- Anthropic stated Moonshot AI used thousands of fake accounts to exchange over 23 million communications with Claude between May and July.
- DeepSeek also allegedly passed sensitive customer information to Claude.
- Seven Chinese AI labs reportedly attempted this type of model distillation in the past seven months.
- U.S. authorities have likened large-scale distillation to industrial-scale theft.
Anthropic has detailed the methods it claims Chinese AI firms employed to replicate the outputs of its Claude models at scale, utilizing fake accounts and illicit intermediary networks. According to a threat intelligence report released by Anthropic, companies such as Moonshot AI and DeepSeek utilized "transfer stations" – intermediary services operating outside China. These services allegedly sent user queries to Claude, and the subsequent responses were then used to train the Chinese firms' proprietary models. Anthropic characterizes this practice as an illicit form of distillation, where a model's performance is enhanced by training on a rival AI's outputs, a tactic U.S. authorities have equated to industrial-scale theft.
Anthropic stated it confirmed instances where information from users of Moonshot AI's Kimi service was relayed to Claude without the users' knowledge. In one cited example, a user submitted surveillance data from CCTV cameras in Chengdu, China, to Kimi for analysis. Due to the intermediary network routing the material to Claude, Anthropic also gained access to this data. The company reported that Moonshot AI used thousands of fake accounts to exchange over 23 million communications with Claude between May and July. DeepSeek reportedly engaged in a similar process, passing sensitive customer information to Claude. In total, seven AI labs based in China have allegedly attempted this form of distillation over the past seven months.
Jacob Klein, head of threat intelligence at Anthropic, told The Wall Street Journal that users were unaware their activity on Kimi was being shared with Claude, adding that such actions would constitute a major scandal if undertaken by a U.S. company. The report also highlighted other alleged misuses of Claude, including its use in hacking and potentially dangerous biological research, such as a user seeking information to modify an avian influenza virus to infect mammals. OpenAI has also reported similar queries related to biological weapons. Furthermore, Anthropic identified instances of AI being used in cyberattacks, with a Chinese hacking group allegedly using Claude to split into sub-agents for reconnaissance and post-intrusion tasks, identifying numerous zero-day vulnerabilities and selecting targets.
