Anthropic Accuses DeepSeek and Other Chinese AI Labs of Illegally Using Claude Data to Train Models
Model distillation can be a legitimate technique in which a more powerful model is queried at scale and its outputs are collected to train a smaller model to replicate its reasoning and coding capabilities. Anthropic, however, accused DeepSeek, MiniMax and Moonshot AI of circumventing Claude's terms of service and regional restrictions. The case touches on U.S.-China AI competition, intellectual property and model security, and could also result in existing safeguards being removed.
On Feb. 23, 2026, Anthropic released an investigation alleging that the three labs used about 24,000 noncompliant accounts to interact with Claude more than 16 million times. MiniMax accounted for more than 13 million interactions, Moonshot AI more than 3.4 million and DeepSeek more than 150,000. Anthropic did not disclose any financial losses. It said it had strengthened account verification and detection systems and shared attack indicators with industry peers and cloud providers.
All Coverage
5 original reportsThe Backstory
The history behind this eventAnthropic Accuses Alibaba of Largest-Ever Distillation Attack on Claude
Anthropic accused Alibaba’s Qwen AI lab of using “distillation” to extract Claude’s software engineering and agentic reasoning capabilities from its outputs. Such practices could circumvent the high cost of training models and have renewed scrutiny in the U.S. Congress over the national security risks of giving Chinese companies access to advanced AI models.
Anthropic recently told the U.S. Senate that Qwen used nearly 25,000 accounts to interact with Claude 28.8 million times, making it the largest distillation attack the company has detected to date. Following the disclosure, Alibaba reportedly instructed employees to uninstall all Claude products. The incident could also spur bipartisan efforts in the United States to consider restrictions on foreign access to AI models.
DeepSeek Reportedly Used Banned Blackwell Chips for Training, Accused by Anthropic of Distillation Attacks
DeepSeek launched R1 in January 2025, achieving performance close to that of leading U.S. models with about $5.6 million in chip-computing costs and sending shockwaves through the AI industry over its low-cost approach. The controversy now centers on two alleged shortcuts: obtaining advanced chips subject to a U.S. export ban and using Claude outputs for training through “model distillation,” raising questions about U.S.-China AI competition and the effectiveness of export controls.
On February 23, 2026, U.S. officials said DeepSeek trained its latest model in China using Nvidia Blackwell chips, possession of which could itself violate export controls. The model could be released as early as the following week. The same day, Anthropic accused DeepSeek, Moonshot AI and MiniMax of using about 24,000 fake accounts to interact with Claude more than 16 million times. DeepSeek accounted for more than 150,000 of those interactions. The three companies did not immediately respond.
China’s Moonshot and Other AI Firms Accused of Stealing Anthropic Claude Technology Through ‘Distillation Attacks’
Model distillation uses the outputs of a powerful model to train a smaller one and can legitimately reduce development costs. But competitors that use fake accounts to evade terms of service and extract Claude responses at scale may violate Anthropic’s intellectual property rights and service restrictions. The dispute also has national security implications, as copied reasoning, tool-use and coding capabilities could operate without the original safeguards.
On February 23, 2026, Anthropic accused Moonshot AI, DeepSeek and MiniMax of using about 24,000 fraudulent accounts to generate more than 16 million interactions with Claude. These included more than 3.4 million interactions by Moonshot, more than 13 million by MiniMax and more than 150,000 by DeepSeek. Distillation concerns resurfaced recently after Moonshot’s Kimi bot identified itself as Claude in a response. Anthropic did not disclose the amount involved or estimate its losses.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →