Anthropic says four Chinese labs pulled 45 million exchanges out of Claude through roughly 49,000 shell accounts. Washington calls it theft. The pattern looks more like gray-market sourcing, and that changes what the fight is actually about.
Anthropic has publicly accused DeepSeek, Moonshot AI, MiniMax and operators tied to Alibaba’s Qwen lab of running large-scale distillation campaigns against Claude, using about 49,000 fraudulent accounts to generate more than 45 million exchanges. The White House and Treasury have since threatened sanctions and Entity List designations. Strip out the moral vocabulary and a familiar business problem shows up: four companies needed an input their supplier refused to sell them, so they built shell buyers, leaned on intermediaries and sized their orders to blend into ordinary demand. Anthropic’s contract remedy is to close accounts. You cannot close your way out of a supply chain, which is why the Treasury Secretary ended up doing the talking instead of Anthropic’s lawyers.
An order you cannot place
Picture yourself running procurement for a factory. One component decides whether your product works. One supplier makes it. That supplier competes with you, has told you no, and has asked its government to make sure the answer stays no.
You have three moves. Build the component yourself, find a second source, or buy it through somebody the supplier will still sell to. Firms have been running the third play since the first embargo, through brokers, shells and freight that takes a scenic route.
Now read the last six months of AI headlines with that in mind.
What happened
The Wall Street Journal published a feature on Friday tracing China’s frontier labs back to a single Tsinghua University lineage, with professor Tang Jie of Z.AI and his former student Yang Zhilin of Moonshot AI at the center. The piece credits the catch-up to a mix of what it calls “ingenuity and imitation,” and notes that Anthropic has accused both companies of violating its policies through large-scale distillation.
That accusation has been building all year. On February 23, Anthropic named DeepSeek, Moonshot and MiniMax, saying the three generated over 16 million exchanges with Claude through roughly 24,000 fraudulent accounts, targeting agentic reasoning, tool use and coding. Anthropic said the activity ran “in violation of our terms of service and regional access restrictions.”
On June 10, Anthropic told the US Senate Banking Committee that operators affiliated with Alibaba and its Qwen lab had run a larger campaign still: more than 28.8 million exchanges through almost 25,000 accounts between April 22 and June 5.
Then Washington took over the microphone. On July 22, White House science and technology policy director Michael Kratsios said the administration had information that Moonshot distilled Anthropic’s Fable model to build Kimi K3, and that the company built an internal platform to “quickly switch between multiple methods of access to avoid detection.” He alleged in the same post that Moonshot had obtained Nvidia GB300 servers, including through Thailand. Treasury Secretary Scott Bessent followed with a sanctions warning and a line built for quoting: “Open source is not open season on American IP.”
The Chinese Embassy in Washington called the claims pure slander. Moonshot and Z.AI have not commented. Researchers have raised a separate objection: Braden Hancock, co-founder of Snorkel AI, told TechCrunch the timeline between Fable’s release and K3 leaves almost no room to train a model that size on distilled outputs.
The backstory
Anthropic is not the only supplier reporting the same losses. OpenAI wrote to US legislators in February describing activity it read as ongoing attempts by DeepSeek to distill frontier models. Google disclosed in the same month that it had disrupted extraction aimed at Gemini’s reasoning through more than 100,000 prompts. Three suppliers, one pattern, one quarter.
The mechanics Anthropic described are worth sitting with. It reported a hydra structure of proxy-based resale networks, with one network alone running more than 20,000 accounts at once and mixing extraction traffic in with ordinary requests. Attribution came from IP correlations, metadata and infrastructure fingerprints rather than from anything the buyers admitted.
Nobody broke in. No credential leaked, no server sat unpatched. The buyers used the product the way it was built to be used, at a volume and cadence chosen so it would not look unusual.
The plan on both sides
Anthropic’s response is detection spending. Behavioral fingerprinting, cross-account analysis, shared technical indicators with other labs and cloud providers, and tighter verification on the account types the campaigns favored, which are the educational, research and startup tiers.
Washington’s response is a different instrument entirely. The State Department circulated a cable in April on unauthorized distillation campaigns. Bessent has put sanctions and Entity List designations on the table. That legal theory, which holds that publishing a model’s weights does not cure an infringement sitting underneath them, has never been tested in a courtroom.
The Chinese labs have their own plan, and they have been executing it in public. Moonshot released Kimi K3 at 2.8 trillion parameters and published the weights, then paused new subscriptions when demand outran its GPUs. Z.AI ships GLM under MIT, and one of those free releases matched a restricted US model on security bug-finding. Alibaba ships much of Qwen under Apache 2.0. Every free download reduces how much anyone in that ecosystem needs a US API in the first place.
The business model angle
Start with what was scarce. Liang Wenfeng of DeepSeek told investors in May that chips, not people, were the widest gap between Chinese and American labs. Researchers at Alibaba and Z.AI report roughly one-fifth the high-end silicon their peers at OpenAI and Google get. Jefferies put Chinese tech capital spending at under a fifth of the US level.
Compute at frontier scale is the input you cannot buy at any price when export controls say no. Model outputs are the input you can buy, or at least appear to buy, for the price of an API call. Distillation converts an unavailable input into an available one. That is substitution under constraint, and it is the oldest move in procurement.

Three things fall out of the numbers that nobody has run.
The orders were throttled. Divide Anthropic’s Alibaba figures and you get about 1,152 exchanges per account across a 44-day window, or roughly 26 per account per day. That is the usage profile of a small development team having a productive Tuesday. Whoever designed that campaign was not trying to drain a well before anyone noticed. They sized each order to sit inside the demand curve. The February campaigns average about 667 exchanges per account, and Anthropic reported that the operators blended suspicious calls with normal ones. Sourcing discipline, not a smash and grab.
Two embargoed inputs, one sourcing operation. Kratsios accused Moonshot of distilling Fable and of routing GB300 servers through Thailand, in the same post, on the same day. The press covered those as two scandals. Read them as one procurement function solving for two restricted components with the same playbook, and Moonshot looks less like a burglar and more like a company that built an office for this.
The remedy gap is the whole story. Anthropic’s contract with a customer who breaks the terms allows it to terminate the account. Against a counterparty operating 25,000 accounts from a jurisdiction where Anthropic cannot practically sue, termination is a restocking fee. Terms of service are worth exactly what you can enforce in the other side’s courts, and here that number rounds to zero. Bessent reached for sanctions because sanctions are what governments hand you when contract law has no reach. Your supplier agreement is a business model assumption, and this one failed quietly for years before anyone priced it.
There is a cost on the supplier’s side too, and it lands on the wrong people. Anthropic now pays to police its own demand, and the friction shows up as verification hurdles on research, education and startup accounts. The honest small buyer covers the cost of the dishonest large one. Ask anyone who has run a marketplace with a fraud problem how that ends. The buyers paying per token already watch their margins move with someone else’s price list.
The risk
Take the counterarguments seriously, because several of them are strong.
Every number here is Anthropic’s allegation. No court, regulator or independent auditor has verified the account counts, the exchange volumes or the attribution. The companies named deny it. Treat the chart above as a disclosure from one interested party.
Hancock’s timing objection cuts at the causal claim rather than the sourcing one. If K3 could not have been trained on Fable outputs in the weeks available, distillation explains motive without explaining capability, and the Tsinghua research pipeline the Journal spent 3,000 words on does more of the work than the extraction does.
The sharper problem for anyone building a policy around this: the second source already exists and it is free. Meta published Muse Glimmer under Apache 2.0 on August 10 and has promised weights for Muse Spark 1.2. OpenAI shipped gpt-oss under Apache 2.0 a year earlier. Qwen and GLM carry permissive licenses of their own. A buyer who can distill a capable model under a license that permits it has no reason to run 25,000 shell accounts. Meta’s licensing move, whatever Zuckerberg meant by it, converted an uncontracted input into a contracted one for everybody, including the labs Washington wants to cut off. We took that apart in our read of the Muse Glimmer license.
And the tap has a second hand on it. On June 12 the Commerce Department ordered Anthropic to cut off foreign nationals from Fable 5 and Mythos 5, and Anthropic, unable to filter by citizenship, disabled both models worldwide within hours. Paying customers with signed contracts got the same outcome that week as the labs Anthropic had banned. We wrote about what that outage taught buyers outside the US, and the lesson generalizes: a contract with your vendor is not a contract with your vendor’s regulator.
One thing to watch, and it will settle this. If extraction volumes fall after a US frontier model ships with open weights, access was the binding constraint and the supply chain reading holds. If Anthropic discloses another campaign of this size after that happens, the labs were never chasing access. They were chasing a quality tier that free weights do not reach, and the procurement frame is the wrong one.
Quick questions
Is distillation illegal? Not by itself. Labs distill their own models constantly to ship cheaper versions. The dispute is over doing it to a competitor’s model, through accounts created to evade the terms and the regional restrictions, which is a contract question first and an IP question second. No court has ruled on the theory Bessent laid out.
Why does DeepSeek get the headlines with the smallest campaign? Anthropic put DeepSeek at just over 150,000 exchanges, about 0.3% of the four-campaign total and roughly a hundredth of MiniMax’s volume. DeepSeek carries the story because of January 2025, not because of the numbers.
Did the distillation actually make Kimi K3 good? Unproven, and contested by researchers who say the calendar does not allow it. K3’s benchmark performance is real regardless of where the training signal came from.
What is the exposure for a normal company? Any critical input reached through a foreign API carries three risks stacked together: the vendor can change terms, the vendor’s government can suspend service, and your contract remedy is worthless if you cannot enforce it where the vendor sits. June 12 proved the second one is live.
Does buying Chinese models solve it? It swaps one jurisdiction’s switches for another’s. Downloadable weights remove the remote shutoff, which is a real difference, and they add license, support and update questions that a hosted API answers for you.
The Business Model Analyst Take
The distillation fight gets covered as an ethics story because ethics stories are easier to write. Underneath it sits a question every operator should be able to answer about their own business, and most cannot.
Sort your critical inputs into three buckets. Owned, which nobody can take. Contracted and enforceable, where a court you can actually reach will make somebody perform. Contracted but unenforceable, or never contracted at all, which is where the cheap inputs live.
That third bucket is where margin comes from and where companies die. Anthropic sat there for years, selling a product whose most valuable use case was building a competitor, with account termination as its only lever. The Chinese labs sit there too, sourcing from a supplier who wants them gone and a government that can revoke access on a Friday evening. Both sides discovered the same thing in the same year, from opposite ends of the transaction.
The cheapest input in your business is usually the one with no contract behind it. Go find yours and put a number on what happens the week it disappears. If the answer is a scramble, you do not have a supplier. You have a habit.
