Skip to content
Tech News
← Back to articles

US says Chinese firms extracted billions of tokens from frontier AI models

read original get Yubico YubiKey 5C NFC Security Key → more articles
Why This Matters

A joint CISA/NSA/FBI advisory accuses six Chinese AI firms of systematically scraping outputs from US frontier models via fraudulent accounts and proxies to train cheaper rivals, escalating model distillation from a technical debate into a national security matter. If accurate, it undercuts the assumption that massive training spend creates a durable moat for US labs, and it signals tougher API access controls and scrutiny ahead for developers and users.

Key Takeaways
Worth a Look

Yubico YubiKey 5C NFC Security Key — When the story is about fraudulent and shared API accounts being abused at scale, hardware-backed account security suddenly feels very concrete. The YubiKey 5C NFC adds phishing-resistant two-factor login to accounts like Google, GitHub and OpenAI, tapping or plugging in instead of relying on codes anyone can steal. It's a pocket-sized upgrade for developers who hold keys to expensive AI services.

See Yubico YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024.

A joint advisory from CISA, NSA, and the FBI states that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens through millions of requests from frontier AI models from Anthropic, OpenAI, Google, and xAI.

The agencies assess that the scale and sophistication of the operations indicate Chinese government awareness, mentioning that this approach is likely a core development strategy for the offending firms.

AI model distillation is a legitimate technique in which a “student” model learns from the outputs of a well-trained model, helping researchers and developers reduce training costs and speed up AI deployment.

However, as Google warned in February, distillation attacks can occur outside these companies’ controlled environments, abusing API access to extract the knowledge and logic of powerful models and compete with them at a fraction of the training cost.

CISA’s advisory explains that Chinese firms distribute API requests across fraudulent or shared accounts, APIs, cloud services, aggregators, and “transfer station” proxies to bypass geographic restrictions, usage limits, and detection.

Some of the prompts used attempted to expose restricted chain-of-thought reasoning, while automated systems switched providers and checked whether defenders had degraded the responses.

“Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures,” the advisory explains.

“China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.”

DeepSeek and MoonShot AI were marked as the top offenders involved in distilling multiple Claude, GPT, Gemini, and Grok models, followed by MiniMax, which targeted Claude, Gemini, and GPT models.

... continue reading