Anthropic distillation battle turns to dark web, China concerns swell

How dark web hackers are stealing Anthropic and OpenAI's top models

Anthropic’s threat intelligence chief, Jacob Klein, says the company is not afraid of rivals. What concerns him, he argues, is that some activity emerging from China looks less like fair competition and more like outright theft.

According to Klein, foreign adversaries are tapping Anthropic’s Claude models through a technique known as distillation, using the systems to train rival AI products and then market cheaper imitation versions. Distillation can be legitimate in some circumstances, he said, but Anthropic believes that is not the case here.

“There’s an entire illicit ecosystem to try to gain access to Claude and other models,” Klein told CNBC. “This ecosystem goes through any means necessary to evade our controls, so they can spin up accounts at extreme scale.”

The debate over distillation has become one of the most contentious issues in artificial intelligence. When used to pull outputs from another company’s model, the method can help developers build a competing system at a fraction of the original cost. In the U.S., parts of the tech industry are pressing policymakers to avoid new rules, arguing that the strongest and cheapest AI tools should prevail. Others are pushing for tougher enforcement, saying the practice amounts to stealing intellectual property.

In an April memo, the Trump administration said distillation that weakens U.S. research and proprietary information is “unacceptable,” adding that it would consider “a range of measures to hold foreign actors accountable.”

The dispute is escalating at a critical time for Anthropic. The five-year-old AI company has climbed to a private-market valuation of nearly $1 trillion and could go public as soon as October, CNBC has reported.

Chinese startup Moonshot AI unveils new model, closing performance gap with U.S. rivals

Anthropic is specifically pointing to Chinese AI lab Moonshot AI, accusing it of copying the company’s technology. Moonshot’s Kimi K3 model drew major attention in July with a lower-cost AI product described as frontier-level. It has gained traction across Silicon Valley, helped by its cheaper pricing and the relative ease with which companies can customize it.

Klein said Kimi K3 was illegally trained using the latest version of Claude.

“We’ve seen a fair amount of this from China,” Klein said. “This is something that the industry writ large is dealing with.”

Earlier this year, Anthropic alleged Moonshot and two other Chinese AI labs – DeepSeek and MiniMax – distilled its frontier AI models. Anthropic has also accused Alibaba, which makes the Qwen family of models, of conducting a massive “distillation attack” to illegally capture capabilities from Claude. OpenAI and Google have both published reports on distillation and claim they’re fighting the same issue.

Alibaba, DeepSeek, Moonshot and MiniMax didn’t respond to requests for comment.

‘Fraudulent means’

Cybersecurity experts told CNBC that, in addition to China, the threat is also coming from countries like Iran, Russia and North Korea, where use of Claude, Google’s Gemini and OpenAI’s ChatGPT are restricted by the companies due to sanctions.

Klein said many labs in those regions “go through illicit means and fraudulent means to try to gain access to a model.”

One way people are getting around those restrictions is by turning to the dark web, where they can find marketplaces of stolen credit card information and compromised AI accounts. Klein said companies like Moonshot are “spinning up tens of thousands, if not hundreds of thousands of fraudulent accounts.”

Once they’ve accessed Anthropic’s systems, they’re able to ask the models questions and collect responses, which they can use to train their own model, often called the student, Klein said.

A clear sign that distillation is taking place is that a user could be asking thousands of questions, rather than dozens and potentially even creating thousands of accounts to do the same, producing a whack-a-mole scenario for the AI labs, Klein said.

“It’s very hard to fully stop this as a problem, but I think slowing it down is good and worthwhile,” Klein said, adding that foreign companies are able to use the technology with few guardrails.

He pointed to fears like surveillance and possible use in a biological weapons program, and noted what he described as a specific campaign from a China-based entity that was conducting espionage at scale using Anthropic’s technology.

“There is a national security concern at play if malicious actors, bad actors who we don’t trust are gaining access to a more capable models than they could have otherwise through the act of distillation.”

Google takes aim at Anthropic, Microsoft with budget-friendly AI pricing

Travis Lanham, technology chief at cybersecurity firm Armadin and a former Google engineer, said bad actors often go undetected because AI companies are under pressure to make their platforms as accessible as possible as they race against the competition.

“These companies are serving billions of requests,” Lanham said, about the big AI labs. “The millions are relatively small compared to everything and it’s just sneaking in and trying to look like the rest of the crowd.”

Klein acknowledges that, for Anthropic, widespread competition is to be expected and that there are legal methods of distillation. That generally means gaining permissions and following the law on matters like IP and export controls.

“I think competition is great,” Klein said. “The concern here is if you are taking our model, distilling it through fraudulent means, creating millions of fake accounts using stolen credit cards and stolen infrastructure, to then produce a model that doesn’t have safeguards in place.”

WATCH: Anthropic pushes into physical world

Anthropic pushes into physical world with new standard to help AI agents operate machines

Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

George Clooney Backs Mark Ruffalo in Studio Antisemitism Row

George Clooney has joined the growing list of Hollywood figures speaking out…