US federal agencies have published an advisory alleging that six Chinese AI firms have conducted industrial-scale extraction campaigns against US frontier models to accelerate their own development. The joint alert from the NSA, CISA and the FBI names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z[.]AI, and contends that these organisations have been systematically distilling proprietary capabilities from models such as Claude, GPT, Gemini and Grok since at least late 2024.
The advisory describes methods that go beyond ordinary data gathering. It claims the groups sent millions of requests across millions of exchanges to obtain targeted knowledge, including chain-of-thought reasoning and coding skills, to inform their own R1 and V3 models. It also portrays a highly organised operation: premised accounts, shared credentials, use of grey-market proxies or “transfer stations” to mask activity, and prompt injections aimed at misleading competing models.
The document provides concrete detection signals for US AI firms, such as multiple IPs and user agents logging in from shared accounts, non‑stop usage patterns, abnormal subscription-to-API use ratios, and new accounts hitting capacity immediately.
Countermeasures urged are notably proactive, including quietly downgrading degraded responses for suspected distillation accounts to hinder adaptation. The advisory emphasises that exploration of these signals should be interpreted carefully to avoid guessing legitimate activity, and that organisations with large developer teams may see false positives.