The US says Chinese firms have extracted billions of tokens from Frontier AI models

The US says Chinese firms have extracted billions of tokens from Frontier AI models

The US says Chinese firms have extracted billions of tokens from Frontier AI models

U.S. cybersecurity and intelligence agencies say six Chinese AI companies have carried out large-scale distillation attacks on American border AI models since at least late 2024.

A joint advisory from CISA, NSA and the FBI said DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens through millions of requests from frontier AI models from Anthropic, OpenAI, Google and xAI.

The authorities believe that the scale and complexity of the operations indicate the awareness of the Chinese government and note that this approach is likely to be a key development strategy for the companies in question.

AI model distillation is a legitimate technique in which a “student” model learns from the results of a well-trained model, helping researchers and developers reduce training costs and accelerate AI deployment.

However, as Google warned in February, distillation attacks can occur outside of these companies’ controlled environments and abuse API access to extract the knowledge and logic of powerful models and compete with them at a fraction of the cost of training.

CISA’s advisory explains that Chinese companies are distributing API requests through fraudulent or shared accounts, APIs, cloud services, aggregators, and “transfer station” proxies to bypass geographic restrictions, usage limits, and detection.

Some of the prompts used attempted to uncover restricted thought chains, while automated systems switched providers and checked whether defense attorneys had downgraded the answers.

“Advanced industrial-scale distillation tactics include chain of thought (CoT) extraction, automatic failover between paths during blocking attempts, and sophisticated quality assessment frameworks to detect defensive countermeasures.” The advisory explains.

“China-based AI companies that undertake industrial-scale distillation with US AI models experience significantly shorter AI development times and lower financial expenditure to train a frontier model.”

DeepSeek and MoonShot AI were flagged as the top offenders in distilling multiple Claude, GPT, Gemini and Grok models, followed by MiniMax, which targeted Claude, Gemini and GPT models.

Alibaba and StepFun are accused of targeting Claude and GPT models to improve their products, while Z.AI allegedly targeted GPT-5.5 and Claude Opus 4.8.

The review recommends that AI companies improve behavioral and infrastructure-level detection, adapt responses when distillation operations are suspected, and share information about these campaigns with all stakeholders.

Possible indicators include new accounts reaching peak usage immediately, continuous activity without normal human idle time, shared accounts accessed through numerous IP addresses or user agents, identical prompts across multiple providers, unusually high subscription-to-usage ratios, and coordinated switching between access routes.

BleepingComputer has reached out to all six Chinese AI companies for comment and we will add their comments when we receive them.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *