US agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities.NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running industrial-scale extraction campaigns against US frontier models since at least late 2024. The framing is deliberate: this isn’t a footnote to how these companies build AI, the agencies call it the core of their entire development strategy.Distillation is a legitimate and widely used technique. It involves training a smaller AI model to reproduce the answers and capabilities of a larger one. But the advisory says the activity it uncovered went much further. It alleges that the companies sent millions of requests to models such as Claude, GPT, Gemini, and Grok and extracted billions of tokens. “China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy.” states the report. “Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.”The goal was to capture valuable capabilities, including reasoning, coding, and agentic skills that took years and huge amounts of computing power to develop.The advisory provides the most detail about DeepSeek. It claims the company ran an organized campaign against different versions of Claude, GPT, and Gemini between late 2024 and mid-2025 to help develop its R1 and V3 models. The extracted data reportedly included specialized knowledge, such as legal expertise, as well as chain-of-thought reasoning. “Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures. China-based AI companies that conduct industrial-scale distillation against U.S.” continues the advisory. “AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.”This is particularly significant because AI companies usually limit access to a model’s internal reasoning. Getting a model to reveal those steps could therefore give attackers much more than just its final answers.Moonshot AI’s alleged operation shows how fast these campaigns can move once new models ship. The advisory states the company redirected its extraction traffic to a newly released Claude model within 24 hours of launch, which only works if you already have infrastructure sitting ready and monitoring provider releases in real time. That’s not opportunistic scraping; that’s a standing operation built specifically to capture whatever comes out next.The methods described in the advisory suggest a highly organized operation rather than researchers simply making API requests. The companies allegedly bought large numbers of premium accounts and shared them among teams of developers running many sessions at the same time. They also routed traffic through gray-market proxy services, which the advisory calls “transfer stations,” to remove identifying information and avoid detection. StepFun reportedly used pools of accounts and automated systems to spread requests across them, helping bypass rate limits and increase daily spending as the operation grew.The advisory also describes attempts to manipulate the AI models themselves. MiniMax allegedly used prompt injection to convince Claude Code that it was actually a MiniMax product, hoping to make it behave differently. While this detail may sound unusual, it shows how far some of these efforts reportedly went to extract information from competing AI systems.The advisory doesn’t just name and shame, it lays out concrete detection signals for US AI companies to watch for. Shared accounts logging in from multiple IPs and user agents, usage running 24/7 without the natural idle periods a human would produce, subscription-to-API-usage ratios that don’t add up, and brand-new accounts hitting maximum usage immediately instead of ramping up gradually the way legitimate adoption normally does. We must consider that any one of those signals alone might be nothing, but the agencies are betting the combination is a fairly reliable tell.“China-based AI companies leverage techniques not in MITRE ATLAS, demonstrating significant organizational investment, operational maturity, and adaptive capability development distinguishing these campaigns from opportunistic exploitation.” added the advisory.The recommended countermeasures get genuinely aggressive, and one in particular is worth sitting with. The advisory suggests quietly serving degraded, less capable responses to accounts suspected of running distillation campaigns, without ever telling those users their access has been downgraded, specifically so they can’t adjust their extraction technique in response. That’s a notable policy stance from a government advisory: not just detect and block, but actively deceive suspected bad actors about the quality of what they’re receiving.Whatever the geopolitical debate, the practical lesson for companies using frontier AI models is clear. If several employees share enterprise AI accounts, providers will likely monitor usage more closely for the patterns described in the advisory. Heavy legitimate use could sometimes trigger false positives, especially when organizations have many developers making large numbers of requests at the same time.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, AI Models)