Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

Anthropic’s Distillation Battle Moves To The Dark Web As China Fears Grow

Card image cap

Anthropic’s fight against AI model distillation is getting harder to contain.

The Claude maker says foreign AI labs are using sprawling networks of fake accounts, proxy services and compromised credentials to collect Claude outputs at scale. Anthropic’s head of threat intelligence, Jacob Klein, has now told CNBC that parts of that access ecosystem extend into the dark web, where stolen accounts and payment information can help attackers bypass restrictions.

The allegations add another layer to the growing US-China AI dispute. But there’s an important distinction: distillation itself isn’t automatically theft. It’s a standard AI training technique, and the controversy comes from how the training data is obtained.

Anthropic Says Distillation Is Happening At Industrial Scale

Anthropic publicly laid out its strongest evidence in February.

In its investigation into distillation attacks, the company said DeepSeek, Moonshot AI and MiniMax generated more than 16 million exchanges with Claude through roughly 24,000 fraudulent accounts.

Distillation works by using the outputs of a stronger “teacher” model to help train another model. AI companies commonly use the technique on their own systems to create smaller or cheaper versions.

The dispute starts when a rival allegedly collects those outputs without permission and at enormous scale.

Anthropic said Moonshot alone accounted for more than 3.4 million Claude exchanges. Its investigation described hundreds of fraudulent accounts spread across different access routes and targeting capabilities including coding, computer vision and agentic reasoning.

That earlier evidence is stronger than some of the newer claims. The public record around the specific Kimi K3 distillation allegation, for example, still contains important gaps between Anthropic’s documented activity and claims about exactly how individual Moonshot models were trained.

That distinction matters.

The Dark Web Makes Account Blocking A Whack-A-Mole Problem

The newer part of the story is how attackers allegedly obtain access.

Klein told CNBC that an illicit ecosystem has developed around accessing Claude and other restricted AI systems. Cybersecurity experts interviewed by the outlet described dark-web markets containing compromised AI accounts and stolen payment information that can help operators create or acquire access at scale.

Anthropic’s own investigation describes a similar infrastructure problem without focusing specifically on the dark web.

It says proxy operators build what the company calls “hydra clusters” — large networks of fraudulent accounts spread across Anthropic’s API and third-party cloud platforms. When one account disappears, another can take its place.

One proxy network allegedly controlled more than 20,000 fraudulent accounts simultaneously.

That changes the security problem. Anthropic isn’t simply trying to identify someone sending an unusually high number of prompts from one account.

The Fight Is Becoming A US-China Policy Issue

Washington has already moved beyond treating distillation as a private dispute between AI companies.

An April White House memorandum on adversarial AI distillation said the US government had information indicating that foreign entities, mainly based in China, were conducting industrial-scale campaigns against American frontier models.

The memo also made an important distinction. Legitimate distillation remains part of the AI ecosystem, while coordinated attempts to extract proprietary capabilities without permission are considered unacceptable.

Anthropic CEO Dario Amodei has taken a similar position. He has argued against blanket bans on Chinese open-weight models while supporting action against industrial-scale distillation and tighter controls on advanced AI chips.

That nuance matters because Chinese open-weight AI is no longer a fringe part of the market.

As our open-weight AI statistics for 2026 show, Chinese developers now command substantial download activity across major open-model platforms.

So regulators face a tricky line: stop covert extraction without turning every competitive Chinese model into evidence of wrongdoing.

Why This Matters Beyond Silicon Valley

Anthropic frames the issue as more than lost revenue or intellectual property.

The company argues that a model trained through illicit distillation could reproduce powerful capabilities without inheriting the safeguards of the original system. That could matter in areas such as cybersecurity, biological research or automated surveillance.

There’s also a commercial consequence.

If a rival can obtain expensive frontier-model capabilities without paying the full research and training cost, it can potentially offer similar functionality for much less. That puts pressure on the economics of companies spending billions to build closed models.

For South African businesses, the useful takeaway isn’t that Chinese AI is inherently risky. It’s that model provenance is becoming part of vendor risk.

A company choosing an AI model may increasingly need to understand who developed it, where its capabilities came from, what safeguards survived training and whether geopolitical restrictions could suddenly affect access.

We think that’s the larger story here. AI competition is moving from benchmark tables into identity checks, payment networks, cyber defence and national security policy.

FAQs

What Is AI Model Distillation?

AI model distillation uses the outputs of a powerful model to help train another model. The technique itself is legitimate and widely used, but collecting another company’s outputs at scale without permission can violate its terms and trigger intellectual-property disputes.

Which Chinese AI Companies Has Anthropic Accused?

Anthropic has publicly named DeepSeek, Moonshot AI and MiniMax in its February investigation. It said the three labs collectively generated more than 16 million Claude exchanges through around 24,000 fraudulent accounts, although separate claims about how specific newer models were trained may have different levels of public evidence.

Why Is The Dark Web Relevant To Claude Distillation?

Dark-web markets can provide stolen credentials, payment information and compromised accounts that help attackers bypass regional or account restrictions. According to CNBC’s reporting, this makes large-scale distillation harder to stop because operators can continually replace accounts after platforms block them.

The post Anthropic’s Distillation Battle Moves To The Dark Web As China Fears Grow appeared first on Memeburn.