The National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation on Tuesday named six Chinese AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — as running industrial-scale distillation attacks against US frontier models since at least late 2024. The joint statement is the Trump administration's most detailed public accusation to date, and it alleges the firms "likely" acted with Chinese government awareness while extracting capabilities from variants of Claude, GPT, Gemini and Grok.
The agencies estimate the campaigns have saved the six firms significant sums on frontier training, though they declined to publish a dollar figure. Attackers used tens of thousands of fraudulent accounts routed through what the agencies described as a gray market of proxies, running thousands to millions of coordinated queries per domain over periods that stretched from days to months.
“China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model”— US joint agency statement, NSA, CISA and FBI
Attack methods include bulk-buying inference API access under fake identities and using prompt-injection to force models to reveal hidden chain-of-thought reasoning. The agencies singled out DeepSeek for employing prompts "instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step" — a technique aimed at reconstructing the reasoning traces that make frontier models expensive to train.
Key facts
- 01The NSA, CISA and FBI named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as running distillation attacks against US frontier models since late 2024.
- 02Targeted models include variants of [Claude](/claude), GPT, [Gemini](/gemini) and [Grok](/grok), with campaigns spanning days to months and millions of queries per domain.
- 03Attackers used tens of thousands of fake accounts routed through gray-market proxies to bulk-buy premium subscriptions and evade geographic restrictions.
- 04Agencies said Chinese systems can detect a downgraded model and switch to a smarter variant within 24 hours, complicating covert mitigation.
- 05Anthropic previously suggested Alibaba should face criminal punishment for what it called the largest-ever cloning attack on Claude.
DeepSeek was accused of extensive distillation across all four Western model families, targeting agentic functions, assistant behavior, writing and Q&A optimization, and chain-of-thought reasoning. Moonshot AI allegedly rotated between US providers to extract fine-tuning techniques, reinforcement-learning setups, software-engineering skills and math capabilities. Alibaba, MiniMax, StepFun and Z.AI were said to focus on specific models from OpenAI and Anthropic.
The recommended mitigations are aggressive and, in places, awkward for legitimate customers. Agencies want US firms to flag accounts with suspicious subscription-to-usage ratios, new accounts that immediately hit maximum usage, and any pattern consistent with "bulk deployment with pre-engineered templates." They also want stronger identity verification and closer tracking of individual users on enterprise plans.
Where distillation is suspected, the guidance goes further: silently switch offending accounts to a weaker model, or subtly degrade outputs by altering reasoning paths, adding stylistic inconsistencies or shortening responses. Agencies explicitly advised firms to "avoid informing China-based AI company users suspected of distillation campaigns of a switch to a downgraded model" — a stance that puts vendors in the position of secretly serving inferior products to flagged customers.
That approach carries operational risk. The agencies conceded that some Chinese systems can detect when a smarter model is available and switch within 24 hours, and that automated quality-assurance pipelines can distinguish ordinary service issues from deliberate degradation. Legitimate users caught in the sweep may quietly receive worse answers, a scenario OpenAI already encountered last year when its automatic router defaulted to weaker variants unless users typed phrases like "think harder."
China rejected the accusations. Foreign Ministry spokesperson Mao Ning on Wednesday said US agencies should be strengthening AI cooperation "rather than making groundless accusations," and described China's progress as the result of "high-level scientific and technological self-reliance." Chinese Embassy spokesperson Liu Chang earlier called the US posture a smear campaign, and a separate Foreign Ministry statement noted that many US AI firms have themselves used Chinese models for distillation during research and training.
“Relevant individuals in the United States should respect the facts, discard prejudice, and stop smearing and discrediting China's achievements in the development of its artificial intelligence industry”— Liu Chang, Chinese Embassy spokesperson
The named firms did not immediately respond to requests for comment. It is unclear how quickly the recommended detection and silent-downgrade mitigations can be deployed without eroding trust among paying enterprise customers, or how allied governments will be brought into the intelligence-sharing framework the agencies described as essential.
The joint alert marks a shift from AI security being an industry-led concern to being treated as economic statecraft, with US intelligence agencies now willing to name specific commercial firms and prescribe defensive product behavior. For OpenAI, Anthropic, Google and xAI, that is both validation of complaints they have raised for over a year and a new operating constraint: they are now expected to police their APIs on behalf of US competitiveness, absorb the customer-experience cost of doing so, and share what they learn with Washington. Expect tighter enterprise onboarding, more aggressive rate-limiting on high-volume accounts, and a widening gap between what Chinese developers can extract via API and what they can build on top of open-weights models — where none of these mitigations apply.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




