anthropic

Anthropic says Moonshot's Kimi K3 was distilled from Claude

Claude News

anthropic

Anthropic's head of threat intelligence, Jacob Klein, says rival labs are running fraudulent accounts at a scale of tens of thousands to hundreds of thousands in order to pull Claude outputs and train competing models. Speaking to CNBC, he named Moonshot AI and said its Kimi K3 was illegally trained off the newest version of Claude.

At a glance

  • Access is bought on dark web marketplaces that trade stolen credit card data and compromised AI accounts, a route around the restrictions Anthropic, Google and OpenAI apply in sanctioned countries.
  • Anthropic has previously accused DeepSeek, MiniMax and Moonshot of distilling its frontier models, and separately said Alibaba ran a large distillation attack to capture Claude capabilities for the Qwen family.
  • The dispute surfaces as Anthropic, five years old and privately valued at close to $1 trillion, is expected to go public as soon as October, according to CNBC's reporting.

Distillation policing looks like a structural problem rather than a fixable one: the same low-friction signup that drives API adoption is what makes bulk account creation cheap. Klein's framing also raises the stakes beyond commercial loss, tying cheap copies of frontier models to safety guardrails that the copies do not inherit. For a company approaching a listing, an enforcement story that names competitors likely carries regulatory weight as well.

Moonshot's Kimi K3 landed in July as a cheaper frontier-level model

Kimi K3 arrived in July as a cheaper frontier-level offering and has been widely adopted in Silicon Valley, helped by its price and the ease with which companies can tailor it. Klein said it was illegally trained off the newest version of Claude.

Klein said companies like Moonshot are spinning up tens of thousands, if not hundreds of thousands, of fraudulent accounts, built on stolen credit card data and compromised AI accounts sold on dark web marketplaces. He described an entire illicit ecosystem that evades Anthropic's controls to create accounts at extreme scale. What is coming out of the Chinese market, he said, is closer to theft than competition.

A distillation signal is thousands of questions from one account, not dozens

The tell, Klein said, is volume: an account asking thousands of questions rather than dozens, with operators potentially creating thousands of accounts doing the same. Once inside, they query the models and collect responses, which are used to train what the field calls the student model.

Klein described the result as a whack-a-mole scenario and said fully stopping it is very hard, though slowing it down is worthwhile. Travis Lanham, technology chief at cybersecurity firm Armadin and a former Google engineer, told CNBC that large labs serve billions of requests, so millions of fraudulent ones blend into the crowd. He said the pressure to keep platforms accessible amid competition helps bad actors go undetected.

OpenAI and Google have published their own reports on distillation and say they are contending with the same problem, which Klein described as something the industry writ large is dealing with. He said Anthropic has seen a fair amount of this activity from China.

Iran, Russia and North Korea sit alongside China in the fraud picture

Cybersecurity experts told CNBC that the pressure also comes from Iran, Russia and North Korea, where Anthropic, Google and OpenAI restrict access to Claude, Gemini and ChatGPT under sanctions. Labs in those regions go through illicit and fraudulent means to reach a model, Klein said.

Klein tied the practice to national security, citing surveillance risk and possible use in a biological weapons program, and pointed to a China-based entity that he said ran espionage at scale using Anthropic's technology. He also said foreign companies can run the technology with few guardrails. His stated concern is distilled models reaching actors Anthropic does not trust.

Klein said legal distillation exists and generally means obtaining permissions and complying with the law on intellectual property and export controls. His objection, he said, is fraudulent accounts, stolen credit cards and stolen infrastructure being used to produce a model that lacks safeguards.

What the April memo leaves open

In an April memo the Trump administration called distillation that undermines American research and proprietary information unacceptable and said it would explore a range of measures to hold foreign actors accountable, without specifying them. Parts of the US tech sector are lobbying for a crackdown on what they see as IP theft, while others want policymakers to stay out so the most cost-effective AI wins. No listing date has been confirmed.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.