The revelation sends a chilling message to American innovators: our most advanced artificial intelligence is under relentless, state-backed assault from Communist China. This Tuesday, a joint advisory from federal cybersecurity and intelligence powerhouses—CISA, the National Security Agency, and the FBI—laid bare the details of an industrial-scale campaign where six China-based AI companies have brazenly siphoned off proprietary features from leading U.S. models.
The named culprits include DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. These firms, operating with what officials assert is "likely with Chinese government awareness," extracted an astonishing "billions of tokens across millions of requests" from American-made AI systems. The targets? The crown jewels of American AI: variants of Claude, GPT, Gemini, and Grok. This digital plunder, the agencies report, has been ongoing since at least late 2024.
While "knowledge distillation" is a recognized research method where smaller models learn from larger ones, the U.S. agencies drew a sharp distinction. This was no benign academic exercise; they described it as "aggressive, malicious, and targeted distillation activities at an industrial scale." This is not innovation; it is intellectual property theft on a grand scale, driven by a desire to close the technological gap at America's expense.
The advisory meticulously detailed the sophisticated methods employed by Beijing's digital operatives. The Chinese firms routed traffic through a labyrinth of native application programming interfaces (API), remote cloud providers, and third-party aggregators—all designed to strip user metadata and muddy the trail. A murky "gray market" of proxies, dubbed "transfer stations," allowed them to bypass geographic blocks and violate terms of use with impunity. Bulk premium subscriptions, shared across vast developer teams, ensured these massive theft operations remained cost-effective for Beijing.
From DeepSeek's organized campaign to feed stolen data into its R1 and V3 models—targeting everything from Claude 3.7 to GPT-5 and Grok 4—to Moonshot AI's broad assault on Claude Fable 5 and GPT-4o, the pattern is clear. Alibaba, MiniMax, StepFun, and Z.AI each played their part, distilling American innovations to bolster their own Qwen, M2, Step 4, and chain-of-thought reasoning models. MiniMax even audaciously attempted "prompt injections" to deceive Claude Code into believing it was a MiniMax product. One might call that chutzpah, if it weren't so deeply alarming.
Michael Kratsios, Director of the Office of Science and Technology Policy, minced no words. "Large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable," Kratsios declared, echoing a warning from an April 23 White House memo about "industrial-scale campaigns" employing "tens of thousands of proxy accounts" and "jailbreaking tricks." He added, with piercing clarity, that "There is nothing innovative about systematically extracting and copying the innovations of American industry. And there is nothing open about supposedly open models that are derived from acts of malicious exploitation.”
Treasury Secretary Scott Bessent, in July, was equally direct, signaling potential sanctions against Chinese AI developers. "This administration supports open-source models, but what we do not support is IP theft," Bessent affirmed. "If we see, especially, that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft." His assessment cut through the technical jargon: "There’s a very technical AI word for it called distillation, but you and I would call it theft.”
Indeed, this isn't merely a technicality; it's a direct threat to America's economic competitiveness and national security. The agencies warn that these campaigns allow adversaries to "deliberately strip away security protocols from the resulting models and undo mechanisms that ensure those AI models are ideologically neutral and truth-seeking." This has profound implications for the integrity and trustworthiness of future AI systems globally.
Previous reports from Anthropic, the creator of Claude, underscored the scale of this treachery, detailing how DeepSeek, Moonshot AI, and MiniMax created thousands of fraudulent accounts and sent millions of prompts to Claude, brazenly "free-riding" on American ingenuity.
CISA Acting Director Nick Andersen urged American AI companies to "take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies." The advisory recommends proactive measures: scrutinizing anomalous usage, discreetly degrading responses when theft is suspected, and sharing intelligence across the industry.
This aggressive, state-backed intellectual property theft by Beijing is a stark reminder of the ongoing economic warfare waged against the United States. It underscores the critical need for an America First approach that rigorously protects our technological leadership, holds foreign adversaries accountable for their predatory actions, and ensures that American innovation, built on freedom and enterprise, is not simply handed over to those who seek to undermine our strength. Protecting our digital frontier is paramount to safeguarding our national future.