US Names 6 Chinese AI Firms in Frontier-Model Theft Case
Updated
Updated · Ars Technica · Sep 9
US Names 6 Chinese AI Firms in Frontier-Model Theft Case
3 articles · Updated · Ars Technica · Sep 9
Summary
DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI were identified by US agencies as running industrial-scale attacks on American frontier AI models since at least late 2024.
NSA, CISA and the FBI said the firms likely acted with Chinese government awareness to distill capabilities from Claude, GPT, Gemini and Grok, cutting development time and potentially saving billions in training costs.
Tactics included bulk-buying fake accounts to exploit inference APIs and sending thousands to millions of coordinated prompts, often routed through proxy networks to evade geographic restrictions.
Agencies also said attackers used prompt-injection jailbreaks to extract hidden chain-of-thought reasoning; one example alleged DeepSeek asked models to spell out internal reasoning step by step.
US officials urged AI companies and allies to coordinate defenses, including stronger detection of campaigns using tens of thousands of fraudulent accounts, even if tighter safeguards frustrate legitimate users.