# They Stole AI With 24,000 Fake Accounts

Source: https://www.youtube.com/watch?v=sNCPV-Og9A8
Recap page: https://rapidrecap.app/video/sNCPV-Og9A8
Generated: 2026-02-25T01:04:53.438+00:00

---
## Quick Overview

Anthropic revealed that three AI labs—DeepSeek, Moonshot, and MiniMax—conducted industrial-scale distillation attacks, using 24,000 fake accounts to acquire the chain-of-thought reasoning and output pairs from Anthropic's Opus model without permission, which is a violation of terms of service and may be illegal under existing copyright law, prompting Anthropic to publicly expose the activity.

**Key Points:**
- Anthropic identified industrial-scale distillation attacks targeting their Claude model by three AI labs: DeepSeek, Moonshot, and MiniMax.
- The attacks used approximately 24,000 fraudulent accounts and proxy services to extract chain-of-thought training data from the Opus teacher model.
- DeepSeek executed over 150,000 exchanges targeting reasoning capabilities and creating censorship-safe alternatives to policy-sensitive queries.
- Moonshot AI conducted over 3.4 million exchanges targeting agentic reasoning, coding, data analysis, computer-use agent development, and computer vision.
- MiniMax executed the largest attack with over 13 million exchanges, focusing on agentic coding and tool use/orchestration.
- Anthropic claims this data extraction method is essentially stealing the sophisticated reasoning traces developed by the high-cost, US-based frontier models, circumventing export controls aimed at preventing Chinese labs from accessing advanced compute capabilities.
- The company settled a separate copyright infringement lawsuit with authors for $1.5 billion, paying $3,000 per estimated 500,000 books used in training, highlighting the contentious legal landscape around training data.

![Screenshot at 00:21: Anthropic's blog post titled "Detecting and preventing distillation attacks" is displayed, featuring a large padlock graphic, visually representing the security issue being discussed.](https://ss.rapidrecap.app/screens/sNCPV-Og9A8/00-00-21.jpg)

**Context:** The video discusses Anthropic's recent blog post detailing coordinated, industrial-scale "distillation attacks" targeting their large language model, Opus. Model distillation is a technique where a smaller 'student' model learns from the outputs (including internal reasoning or chain-of-thought) of a larger, more capable 'teacher' model. Anthropic exposed that three specific labs—DeepSeek, Moonshot, and MiniMax—were engaging in this process using thousands of fraudulent accounts to illicitly gain access to Opus's proprietary reasoning capabilities, which is costly to develop and potentially violates export controls.

## Detailed Analysis

The video explains Anthropic's discovery of three labs—DeepSeek, Moonshot, and MiniMax—conducting industrial-scale model distillation attacks against their Opus teacher model. Distillation involves training a smaller student model on the outputs and reasoning traces of a larger model. Anthropic attributes these campaigns, which involved 24,000 fake accounts and proxy services, to three labs: DeepSeek (over 150,000 exchanges targeting reasoning and censorship-safe alternatives), Moonshot AI (over 3.4 million exchanges targeting agentic reasoning and tool use), and MiniMax (over 13 million exchanges targeting agentic coding and tool use). The core issue, according to the speaker, is that these labs are stealing the costly, proprietary reasoning developed by US-based frontier models without permission, potentially circumventing US export controls designed to restrict Chinese labs from accessing advanced compute capabilities. The speaker also draws a parallel to Anthropic's existing legal troubles, noting that Anthropic recently settled a copyright infringement lawsuit with authors for $1.5 billion, highlighting the industry's general struggle with data legality, even though Anthropic argues that the distilled models themselves might not retain copyrighted material directly.

### Model Distillation Process

- Input data (Internet, Books, Any Data) feeds Opus (Teacher)
- Opus sends outputs/chain-of-thought to Student Model
- Student Model trains Haiku (Final Model)

### Attacked Labs and Scale

- DeepSeek (150,000+ exchanges, targeting reasoning/censorship-safe alternatives)
- Moonshot AI (3.4M+ exchanges, targeting agentic reasoning/coding/vision)
- MiniMax (13M+ exchanges, targeting agentic coding/tool use)

### Anthropic's Argument

- Distillation steals proprietary reasoning traces developed at immense cost, potentially violating export controls designed to restrict adversaries like China from accessing advanced capabilities.

### Legal Context/Controversy

- Anthropic settled a separate $1.5B copyright lawsuit with authors (paying $3,000 per 500,000 books), yet they claim the distillation attacks are not illegal because the distilled output might not contain copyrightable material directly.

![Screenshot at 00:21: Anthropic's blog post titled "Detecting and preventing distillation attacks" is displayed, featuring a large padlock graphic, visually representing the security issue being discussed.](https://ss.rapidrecap.app/screens/sNCPV-Og9A8/00-00-21.jpg)
![Screenshot at 01:07: Diagram illustrating model distillation: Data sources feed Opus \(Teacher\), which trains a Student Model, which in turn trains the final model \(Haiku\).](https://ss.rapidrecap.app/screens/sNCPV-Og9A8/00-01-07.jpg)
![Screenshot at 01:17: Highlighting the cost to train frontier models, referencing Sam Altman's estimate of over $100 million in GPU spend alone for GPT-4 scale training.](https://ss.rapidrecap.app/screens/sNCPV-Og9A8/00-01-17.jpg)
![Screenshot at 04:46: Anthropic's blog post listing the three responsible labs: DeepSeek, Moonshot, and MiniMax, and detailing the scale of their attacks.](https://ss.rapidrecap.app/screens/sNCPV-Og9A8/00-04-46.jpg)
![Screenshot at 08:14: TechCrunch headline reporting Reddit suing Anthropic for allegedly using training data without proper licensing, illustrating broader data legality issues in the industry.](https://ss.rapidrecap.app/screens/sNCPV-Og9A8/00-08-14.jpg)
