Detecting and preventing distillation attacks
Anthropic says DeepSeek, Moonshot AI and MiniMax ran distillation campaigns through about 24,000 fraudulent accounts, generating over 16 million exchanges with Claude.
A public accusation with numbers, namely 13M+ exchanges for MiniMax, 3.4M+ for Moonshot and 150K+ for DeepSeek. The targets were DeepSeek's reasoning and reward modeling, Moonshot's agentic reasoning, coding and vision, and MiniMax's agentic coding and tool use. Anthropic says it saw MiniMax pivot within 24 hours of a new model release.
- Date
- Monday, 23 February 2026
- Lab
- Anthropic
- Kind
- paper
- Access
- paper only
Figures
| Measure | Value | Measured by |
|---|---|---|
| Fraudulent accounts (combined) | about 24,000 via proxy 'hydra cluster' services | company |
| Exchanges generated (combined) | 16M+ MiniMax 13M+, Moonshot 3.4M+, DeepSeek 150K+ | company |
Allegations are Anthropic's own; the named labs' responses were not checked. Fable 5 (2026-06-09) added distillation-triggered fallback classifiers and Fable 5.1 (2026-09-01) added preserved-thinking controls.
Sources
This record was checked against its sources on 6 October 2026. How we check