Skip to content

Science1 publisher3 min readPublished

Anthropic attributes 16 million Claude exchanges to 24,000 fraudulent accounts

The company names DeepSeek, Moonshot and MiniMax, and says the accounts reached Claude through commercial proxy resellers, in breach of the regional limits it sets because it does not sell in China. Its case rests on account-level traffic patterns.

The Scientist · Science desk

Illustration accompanying Anthropic attributes 16 million Claude exchanges to 24,000 fraudulent accounts

What happened

  • Anthropic says DeepSeek, Moonshot and MiniMax generated more than 16 million interactions with Claude through around 24,000 fraudulent accounts, breaking its terms of service and its regional access limits.
  • For the DeepSeek cluster, Anthropic cites synchronized traffic across accounts, identical patterns, shared payment methods and coordinated timing, which it attributes to load balancing meant to avoid detection.
  • Anthropic says it caught the MiniMax campaign while it was still running, and that nearly half of the traffic moved to Claude's newly released model inside 24 hours.
  • The access arrived through commercial proxy services that resell Claude and other frontier models at scale, which Anthropic calls hydra cluster architectures.

Compiled by The ScientistSomething wrong?How this is made

Why it matters

  • constraint Gogia's reading puts frontier outputs outside export-control rules, so keeping them away from a restricted lab is fraud detection and contract enforcement paid for by the model provider.
  • decision The proxy resellers sit between the provider and the buyer. Every provider now has to decide how much reseller revenue it will price against the cost of vetting where that traffic ends up.
  • contradiction Shah puts the foundation model industry's own web scraping and this distillation on the same footing. With no settled law on who owns synthetic data, that weakens a consent-based objection.

Sixteen million interactions spread over about 24,000 accounts averages roughly 667 exchanges per account [1]. That average describes exposure, meaning how much Claude output left. How much of it landed as capability inside the three companies' models is a separate quantity, and it would show up in evaluations of those models, not in Anthropic's traffic logs.

Moonshot's share was more than 3.4 million exchanges, aimed at agentic reasoning and tool use, coding and data analysis, computer-use agent development, and computer vision to reconstruct Claude's reasoning traces [8]. Add the three campaigns and the total comes to about 16.55 million exchanges [2]. MiniMax is roughly 79 percent of that and DeepSeek under 1 percent [3]. DeepSeek's 150,000 exchanges went after reasoning across diverse tasks [6], a different job from 13 million exchanges of agentic coding, and one that plausibly needs fewer and richer traces.

Anthropic's account-level signals establish that the accounts were operated together. Attributing them to a named company is a second inference. Computerworld's account does not say how Anthropic drew it, and none of the three companies is quoted [4].

The company has framed the campaigns partly as a national security matter, arguing that illicitly distilled models could undermine US efforts to control the spread of advanced AI capabilities, especially if influenced by the Chinese Communist Party [14].

Sanchit Vir Gogia, CEO and chief analyst at Greyhound Research, said: "It is critical to separate hardware restrictions from service access. US export controls have concentrated primarily on advanced semiconductors, high-performance computing infrastructure, and, in certain regulatory moments, specific categories of advanced AI model weights. There is no universal prohibition on offering API access to large language models in China" [15]. Gogia added that the Bureau of Industry and Security continues to refine licensing frameworks for advanced computing commodities and high-capability systems, and that a company knowingly supporting training activity for restricted entities, particularly those tied to military or strategic objectives, could become exposed without shipping hardware [16]. Many US providers already limit availability in China through business policy and compliance posture, beyond what is strictly required [17].

Distillation means training a less capable model on the outputs of a more advanced one [3], and the practice sits inside an older argument about training data. Neil Shah, vice president at Counterpoint Research, said: "Just as many of the foundation models have been built by indexing the vastness of the internet, often without the explicit consent of creators or piggybacking on other search engines' content, the newer entrants are in many instances going through the same routes of distillation and optimization" [12]. Shah said the disagreement over who owns synthetic data, and whether it is acceptable to train on it, especially in open models, is mostly legally undefined [13].

What to watch

  • Whether Anthropic publishes the method that linked the account clusters to the three named companies, or lets an outside party check it.
  • Any response from DeepSeek, Moonshot or MiniMax, and any evaluation showing what the harvested traffic did to their models.
  • Whether BIS licensing language extends beyond semiconductors and model weights to cover API service access.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories