✨ From vibe coding to vibe deployment. UBOS MCP turns ideas into infra with one message.

Learn more
Andrii Bidochko
  • Updated: February 23, 2026
  • 6 min read

Anthropic Accuses Chinese AI Labs of Claude Espionage Amid US AI Chip Export Debate

Anthropic claims that three Chinese AI labs—DeepSeek, Moonshot AI, and MiniMax—created more than 24,000 fake accounts to harvest millions of interactions with its Claude model, a move that has intensified the U.S. debate over AI‑chip export controls.

Anthropic’s Accusations: A Quick Overview

In a detailed blog post released on February 23, 2026, Anthropic accused three Chinese AI startups of orchestrating a massive model‑extraction campaign against its flagship large‑language model, Claude. According to the company, the labs generated over 16 million conversational exchanges using more than 24,000 synthetic user accounts. The alleged goal: to distill Claude’s most advanced capabilities—agentic reasoning, tool use, and code generation—into their own proprietary models.

The revelations arrive at a critical moment when Washington is wrestling with whether to tighten or relax export restrictions on high‑performance AI chips, a policy tool that could directly affect the feasibility of large‑scale distillation attacks.

Who Are the Accused Labs?

The three companies named by Anthropic are:

  • DeepSeek – Known for its open‑source R1 reasoning model and the upcoming DeepSeek V4, which claims to surpass both Claude and ChatGPT in coding tasks.
  • Moonshot AI – Recently launched the Kimi K2.5 model and a coding agent that emphasizes tool‑use and vision capabilities.
  • MiniMax – A fast‑growing startup that released a suite of agentic tools aimed at enterprise automation.

DeepSeek’s Extraction Footprint

Anthropic tracked more than 150,000 Claude interactions originating from DeepSeek‑controlled accounts. The focus was on “foundational logic and alignment,” especially on how Claude handles policy‑sensitive queries and censorship‑safe alternatives. This data trove is believed to have fed DeepSeek’s upcoming V4 model, which industry insiders say could rival the best U.S. offerings.

Moonshot AI’s Massive Scale

Moonshot AI’s activity dwarfed its peers, with over 3.4 million exchanges. The lab targeted a broad spectrum of Claude’s abilities:

  • Agentic reasoning and autonomous tool use
  • Advanced coding and data‑analysis workflows
  • Computer‑vision prompts and multimodal reasoning

Their public release of Kimi K2.5 shortly after the alleged extraction suggests a direct link between the stolen data and the new model’s capabilities.

MiniMax’s Focus on Agentic Coding

MiniMax logged roughly 13 million Claude interactions, primarily aimed at “agentic coding, tool orchestration, and execution pipelines.” Anthropic observed that MiniMax redirected nearly half of its traffic to specifically harvest Claude’s latest releases, indicating a systematic approach to model replication.

Understanding the Fake‑Account Scale and Distillation Technique

Distillation is a well‑known method where a smaller “student” model learns from the outputs of a larger “teacher” model. While legitimate labs use it to create efficient versions of their own models, the technique can be weaponized when a competitor feeds a foreign model with massive amounts of teacher data.

Why 24,000+ Accounts Matter

Creating tens of thousands of synthetic identities allows an attacker to bypass rate limits, avoid detection, and simulate diverse user behavior. This scale is essential for two reasons:

  1. Data Diversity: Different prompts, contexts, and follow‑up questions expose the full breadth of Claude’s reasoning pathways.
  2. Statistical Significance: Large sample sizes reduce noise, enabling the student model to capture subtle patterns such as safety mitigations and alignment nuances.

The Role of Advanced AI Chips

Anthropic’s blog emphasizes that “the scale of extraction … requires access to advanced chips.” Training a distilled model that mirrors Claude’s performance demands high‑throughput GPUs or specialized AI accelerators, which are precisely the components currently under export‑control scrutiny.

U.S. AI‑Chip Export Controls: The Policy Battlefield

The United States is currently debating whether to tighten restrictions on cutting‑edge AI chips such as Nvidia’s H200. Proponents argue that limiting chip sales to China will curb illicit model‑extraction and reduce national‑security risks. Opponents claim that overly restrictive policies could stifle legitimate research collaborations and hurt U.S. companies’ global competitiveness.

Key Players in the Debate

  • Congressional Leaders: Several Senate committees have called for a review of the AI chip export controls policy, citing the Anthropic allegations as evidence of “AI espionage.”
  • Industry Coalitions: The UBOS partner program and other AI consortia are lobbying for a balanced approach that protects innovation while addressing security concerns.
  • Think‑Tanks: Dmitri Alperovitch of the Silverado Policy Accelerator warned that “the rapid progress of Chinese AI models has been fueled by theft via distillation,” urging stricter export bans.

Potential Impact on the AI Ecosystem

If the U.S. tightens export controls, Chinese labs may face higher hardware costs, slowing down both legitimate research and illicit distillation. Conversely, a relaxed regime could enable faster model development on both sides, potentially escalating the “AI arms race.”

Quotes from Anthropic and U.S. Officials

“The scale of extraction performed by DeepSeek, MiniMax, and Moonshot demonstrates a clear need for robust export controls. Without limiting chip access, we risk enabling systematic theft of frontier AI capabilities.” – Anthropic spokesperson

“These distillation attacks are not just a commercial threat; they pose national‑security risks by potentially stripping safety layers from powerful models.” – U.S. Department of Commerce official

Visual Insight: The Scale of the Attack

Anthropic AI espionage illustration
Illustration of Anthropic’s claim that over 24,000 fake accounts were used to extract Claude’s capabilities.

Original TechCrunch Report

For the full investigative piece, see TechCrunch’s article: Anthropic accuses Chinese AI labs of mining Claude as US debates AI chip exports.

Related UBOS Resources

Understanding the broader AI landscape can help businesses navigate these geopolitical shifts. UBOS offers a suite of tools and insights:

  • UBOS platform overview – A unified environment for building, deploying, and securing AI applications.
  • AI espionage – In‑depth analysis of model‑theft techniques and defensive strategies.
  • AI YouTube Comment Analysis tool – Leverage AI to monitor sentiment trends that could signal emerging threats.
  • AI SEO Analyzer – Optimize your content for both human readers and AI search engines.
  • AI marketing agents – Automate outreach while staying compliant with evolving export regulations.
  • UBOS pricing plans – Flexible pricing that scales with your AI workload, whether you’re a startup or an enterprise.

Future Outlook: What Comes Next?

Anthropic’s accusations have set a precedent for publicizing AI‑theft incidents. Expect the following trends over the next 12‑18 months:

  1. Increased Transparency: More AI firms will publish “model‑theft logs” to pressure policymakers.
  2. Regulatory Action: The U.S. may introduce stricter licensing for AI‑chip sales, potentially mirroring export‑control regimes used for advanced semiconductors.
  3. Defensive Innovation: Companies will invest in watermarking, model‑fingerprinting, and real‑time usage monitoring to detect illicit distillation.
  4. Strategic Partnerships: Startups will align with platforms like Enterprise AI platform by UBOS to leverage secure, audited infrastructure.

For analysts and journalists, the key takeaway is that AI espionage is no longer a fringe concern—it is a mainstream geopolitical issue that intertwines technology, policy, and national security.

Conclusion

Anthropic’s claim that DeepSeek, Moonshot AI, and MiniMax deployed a massive network of fake accounts to siphon Claude’s capabilities underscores the urgent need for robust export controls on AI chips and stronger defensive measures against model‑extraction. As the United States debates the future of AI‑chip exports, the industry must balance innovation with security, ensuring that the next generation of AI models is built on trust rather than theft.


Andrii Bidochko

CTO UBOS

Andrii Bidochko is an AI entrepreneur and researcher focused on AI agents, reinforcement learning, and autonomous systems. He writes about the technologies shaping the future of machine intelligence, from frontier models and agent architectures to real-world AI applications.

Sign up for our newsletter

Stay up to date with the roadmap progress, announcements and exclusive discounts feel free to sign up with your email.

Sign In

Register

Reset Password

Please enter your username or email address, you will receive a link to create a new password via email.