Skip to content

Leadership1 publisher3 min readPublished

Anthropic accuses three rival labs of extracting 16 million Claude exchanges through fake accounts

Anthropic ties the traffic to DeepSeek, Moonshot and MiniMax through IP correlation, request metadata and unnamed industry partners. The DeepSeek campaign it quantifies is under 1 percent of the alleged total.

The Board Room · Leadership desk

Photograph accompanying Anthropic accuses three rival labs of extracting 16 million Claude exchanges through fake accounts
Photo: nbcnews.com

What happened

  • Anthropic said DeepSeek, Moonshot and MiniMax generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts, breaking its terms of service and regional access restrictions.
  • It attributed each campaign with high confidence using IP address correlation, request metadata and infrastructure indicators, plus corroboration in some cases from industry partners it did not name.
  • All three campaigns went after the capabilities Anthropic calls its most differentiated: agentic reasoning, tool use and coding.
  • Anthropic argued the extraction reinforces the case for chip export controls, because running distillation at that scale requires access to advanced chips.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • constraint Detection rests on volume, prompt structure and proxy use looking abnormal, so an enterprise pushing high-volume agentic traffic through an aggregator now resembles the profile vendors are policing.
  • exposure Three named companies sit under a public fraud accusation, and nothing about it is adjudicated. Anyone shipping products on their models carries that supplier question.
  • decision Account provenance moves into diligence: who holds the API keys, whether a reseller pools them, and which subsidiaries fall inside a vendor's regional access restrictions.
  • contradiction Anthropic's finding cuts against reading DeepSeek's progress as proof that export controls failed, and Anthropic is also the party arguing for those controls.

Divide the alleged volume by the alleged accounts and the average account produced about 667 exchanges [16]. That is a modest figure for a single account. The pattern Anthropic describes becomes visible only above the account level. It shows up by correlating IP ranges, request metadata and infrastructure indicators across thousands of accounts, and in some cases by comparing notes with industry partners who saw the same actors on their own platforms [4].

Anthropic puts the DeepSeek campaign at more than 150,000 exchanges [6], under 1 percent of the 16 million it alleges in total [17]. That leaves roughly 15.8 million exchanges inside the Moonshot and MiniMax campaigns [18]. The DeepSeek detail is the specific part of the account. The prompts, Anthropic said, asked Claude to imagine and articulate the internal reasoning behind a completed response and write it out step by step, producing chain-of-thought training data at scale [9]. Rubric-based grading tasks, according to the same post, "made Claude function as a reward model for reinforcement learning" [7]. Accounts shared payment methods and ran on coordinated timing, which Anthropic described as load balancing to increase throughput and avoid detection [8].

Anthropic wrote that it "has consistently supported export controls to help maintain America's lead in AI" [13]. It uses this finding to argue that restricted chip access limits both direct model training and the scale of illicit distillation [14]. The company is accuser and evidence custodian, and it has an interest in the policy inference. Its account does not include a response from DeepSeek, Moonshot or MiniMax [19]. What makes the claim testable is that other vendors hold the same class of logs, and Anthropic said some partners had already observed the same actors and behaviors [4].

The detection signals are what buyers should read against their own usage. Anthropic said the campaigns used fraudulent accounts and proxy services, and that the volume, structure and focus of the prompts differed from normal patterns [10]. Those descriptors also fit legitimate deployments: a reseller pooling keys under one payment instrument, or an evaluation harness firing structured prompts at high volume from one address range. The violations cited are terms of service and regional access restrictions [2], both contract terms.

This quarter the change is contractual and detection-side. Vendors tighten account provenance, and the customers who resemble an extraction ring by accident absorb the friction of proving they are not one. Whether illicit distillation acquires a legal definition is a question of years. Anthropic wrote that "the window to act is narrow, and the threat extends beyond any single company or region" [11]. Addressing it, the company said, "will require rapid, coordinated action among industry players, policymakers, and the global AI community" [12].

What to watch

  • Whether DeepSeek, Moonshot or MiniMax answer the attribution publicly, and whether any of them dispute the IP and payment-method evidence.
  • Whether the industry partners Anthropic credits publish their own detections of the same accounts. Published detections would make this a cross-vendor record.
  • Whether vendors convert anti-distillation controls into enterprise contract language on account provenance, proxy use and reseller key pooling.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories