# Caught Distilling from Claude?

Source: https://www.youtube.com/watch?v=YemMd6-cM0Q
Recap page: https://rapidrecap.app/video/YemMd6-cM0Q
Generated: 2026-02-24T15:33:31.721+00:00

---
## Quick Overview

Anthropic publicly accused three AI labs—DeepSeek, Moonshot, and MiniMax—of orchestrating industrial-scale distillation attacks against their Claude models, involving over 16 million exchanges generated through approximately 24,000 fraudulent accounts to illicitly extract capabilities like agentic reasoning and coding.

**Key Points:**
- Anthropic identified industrial-scale distillation campaigns targeting their Claude models by three AI laboratories: DeepSeek, Moonshot, and MiniMax.
- The total illicit activity involved over 16 million exchanges generated through approximately 24,000 fraudulent accounts, violating terms of service.
- DeepSeek accounted for over 150,000 exchanges, targeting reasoning capabilities and using rubric-based grading tasks to distill Claude's function as a reward model for reinforcement learning.
- Moonshot AI employed hundreds of fraudulent accounts across multiple access pathways, targeting agentic reasoning, coding, tool use, and computer vision, totaling over 3.4 million exchanges.
- MiniMax conducted the largest operation with over 13 million exchanges, focusing on agentic coding and tool use/orchestration.
- The methodology involved prompting Claude to articulate internal reasoning to generate chain-of-thought training data at scale, which is key to illicit knowledge extraction.
- The speaker notes that Anthropic was sued last year for using over 7 million pirated books to train Claude, resulting in a $1.5 billion settlement, highlighting ongoing data sourcing controversies in the industry.

![Screenshot at 00:00: Diagram illustrating the knowledge transfer process from a large Teacher Model \(Claude\) to a smaller Student Model via distillation using data.](https://ss.rapidrecap.app/screens/YemMd6-cM0Q/00-00-00.jpg)

**Context:** The video discusses Anthropic's public announcement regarding large-scale attempts by competing AI labs to extract proprietary knowledge from their Claude language models using a technique called 'distillation.' The speaker references Anthropic's official blog post detailing how DeepSeek, Moonshot, and MiniMax allegedly used tens of thousands of fake accounts to query Claude extensively for its advanced capabilities. This context is further framed by referencing a major lawsuit against Anthropic itself for using copyrighted material in its own training data, suggesting a complex ethical landscape around model training and knowledge extraction in the AI industry.

## Detailed Analysis

The video explains Anthropic's accusation that three AI labs—DeepSeek, Moonshot, and MiniMax—conducted industrial-scale distillation attacks to steal capabilities from their Claude models. Anthropic detected these campaigns, which utilized approximately 24,000 fraudulent accounts to generate over 16 million exchanges with Claude. The attacks specifically targeted sophisticated capabilities like agentic reasoning, coding, tool use, and computer vision. DeepSeek contributed over 150,000 exchanges, focusing on reasoning and using Claude's outputs as a reward model for reinforcement learning. Moonshot AI used hundreds of fraudulent accounts for over 3.4 million exchanges targeting reasoning, coding, and computer vision. MiniMax was responsible for the largest volume, over 13 million exchanges, focusing on agentic coding and orchestration. A notable technique employed was asking Claude to articulate its internal reasoning to generate chain-of-thought training data. The speaker contrasts this by pointing out that Anthropic itself settled a major piracy lawsuit for $1.5 billion last year for training on copyrighted books, suggesting hypocrisy in the public accusations against the other labs, especially since the output of such distillation might be considered 'open source' by the perpetrators.

### Knowledge Distillation Overview

- Diagram shows Teacher Model distilling knowledge to a smaller Student Model via data and knowledge transfer
- Distillation is a widely used technique, but here it is being used illicitly by competitors.

### Accused Labs and Scale

- DeepSeek (150k+ exchanges, targeting reasoning/RL grading)
- Moonshot (3.4M+ exchanges, targeting reasoning/coding/vision)
- MiniMax (13M+ exchanges, targeting agentic coding/orchestration).

### Illicit Techniques

- Attackers used fraudulent accounts, proxy services, synchronized traffic, and load balancing to evade detection and extract specific capabilities like chain-of-thought reasoning.

### Industry Context/Controversy

- Speaker notes the irony of Anthropic making these accusations given they recently settled a $1.5 billion lawsuit for training Claude on copyrighted books without permission, highlighting hypocrisy in the open source debate.

### Future Implications

- Speaker expresses curiosity about the next models released by DeepSeek and whether they will incorporate the stolen capabilities effectively, noting that open-source models may not be trained on these outputs.

![Screenshot at 00:00: Diagram illustrating the knowledge transfer process from a large Teacher Model \(Claude\) to a smaller Student Model via distillation using data.](https://ss.rapidrecap.app/screens/YemMd6-cM0Q/00-00-00.jpg)
![Screenshot at 00:16: Scene from a movie parodying a tense confrontation, with one person yelling about '16 million exchanges, Jian Yang!' following Anthropic's accusation.](https://ss.rapidrecap.app/screens/YemMd6-cM0Q/00-00-16.jpg)
![Screenshot at 00:35: Anthropic blog post titled 'Detecting and preventing distillation attacks' featuring a padlock graphic.](https://ss.rapidrecap.app/screens/YemMd6-cM0Q/00-00-35.jpg)
![Screenshot at 01:51: Google Cloud Threat Intelligence report cover mentioning Distillation, Experimentation, and Integration of AI for Adversarial Use.](https://ss.rapidrecap.app/screens/YemMd6-cM0Q/00-01-51.jpg)
![Screenshot at 02:12: Close-up of Anthropic's report text highlighting the three malicious campaigns and the targeted capabilities \(agentic reasoning, tool use, coding\).](https://ss.rapidrecap.app/screens/YemMd6-cM0Q/00-02-12.jpg)
