The NSA, CISA, and FBI jointly accused six Chinese AI firms—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—of conducting industrial-scale attacks to distill proprietary capabilities from US frontier AI models since at least late 2024. The agencies alleged the firms likely acted with Chinese government awareness and targeted variants of Claude, GPT, Gemini, and Grok, potentially saving billions in development costs. The joint statement warned that these distillation activities at industrial scale extract restricted proprietary functionalities and capabilities of US frontier AI models.

The attack methods include exploiting AI model inference APIs through bulk-buying fake accounts that execute highly coordinated queries with identical or similar prompt texts, ranging from thousands to millions on similar topics. Another method involves prompt injection techniques to jailbreak models, including crafting prompts that force models to reveal their hidden chain-of-thought reasoning—for example, DeepSeek employed prompts instructing models to articulate and write out their internal reasoning step by step.

Agencies recommended stepped-up monitoring for anomalous and malicious prompts, accounts, networks, and behaviors to combat these activities. They noted that Chinese firms rely on bulk procurement of fake accounts and "gray market proxies" to route distillation requests through multiple pathways, evading geographical restrictions. The agencies stated these campaigns span days to months with query volumes in the thousands to millions per domain, far exceeding legitimate research or development use cases.