Fetching from the wire…
Public story · 2026-09-09 · high
NSA, CISA and FBI say DeepSeek, Alibaba and four others pulled billions of tokens from Claude, GPT, Gemini and Grok since 2024.
Why now: The advisory carries the designation AA26-251A and is current as of September 9, 2026.
Six Chinese AI companies extracted billions of tokens from US models since 2024, according to a joint advisory from the NSA, CISA and FBI. DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI are named. The advisory, designated AA26-251A, lists which US model each firm allegedly targeted, pulling from Claude, GPT, Gemini and Grok across millions of requests.
For the six firms, this is a federal government putting their names on a specific accusation rather than a general warning about Chinese AI. For Anthropic, OpenAI, Google and xAI, it's confirmation their production APIs were the extraction point at industrial scale, not lab benchmarks.
The agencies draw a line between two things. Distillation, training a smaller model on a larger one's outputs, is a normal research technique. What the advisory describes is different: extraction of restricted proprietary capabilities at a scale it calls malicious, not academic. It puts all six firms on the wrong side of that line.
The sharper claim is about cost. DeepSeek has said its training run cost $5.6 million. The advisory argues that figure only holds if you ignore what it cost to build the data the model trained on, tokens pulled from systems that took far more than $5.6 million to build in the first place.
If that argument holds, it reframes more than one company's public relations. The next lab claiming a similarly cheap training run will need to show where its training data came from, not just what the run itself cost.
The advisory doesn't say how the agencies counted the tokens, or whether enforcement follows the naming. Watch whether Anthropic, OpenAI or Google change API rate limits or terms of service in response. That would be the first sign this moves past attribution.
Each link below shares sources, entities, or timing with this story.
25,000 fake accounts. 28.8 million Claude conversations. Six weeks. And the thing they were harvesting wasn't trivia, it was software engineering and agentic reasoning. In a June 24 letter to US senators and the White House, Anthropic alleged that operators tied to Alibaba's Q...
Anthropic identified 24,000+ fraudulent accounts generating 16M+ exchanges with Claude from DeepSeek, Moonshot AI, and MiniMax. The agent-specific targeting is key: Moonshot (3.4M exchanges) targeted agentic reasoning and tool use; MiniMax (13M) targeted agentic coding; DeepSe...
Moonshot AI released Kimi K3, a sparse mixture-of-experts activating 16 of 896 experts per token. That's about 1.8% of the pool live at any moment, with a 1M-token context window and native vision. Two new architectural pieces show up: Kimi Delta Attention and Attention Residu...
DeepSeek, Moonshot AI, and MiniMax created 24,000 fraudulent accounts generating 16 million exchanges to extract Claude's outputs. 33.5 million views, 55,000 likes. First time Anthropic publicly named competitors and quantified IP extraction scope. Source
Anthropic published technical details of distillation attacks by DeepSeek, MiniMax, and Moonshot AI — 24,000 fraudulent accounts generating 16M+ exchanges targeting Claude's most differentiated capabilities: agentic reasoning, tool use, and coding. MiniMax led with 13M exchang...
Anthropic formally accused DeepSeek, Moonshot AI, and MiniMax of using 24K fake accounts and 16M exchanges to extract Claude's capabilities. The targeting specifically hit agentic reasoning, tool use, and coding — the exact capabilities powering the tools builders use daily. M...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.