Inside the Extraction Playbook
On September 8, 2026, the NSA, CISA, and FBI released joint advisory AA26-251A warning that 'China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities' [1]. The advisory and Anthropic's parallel investigation describe a common playbook: gray-market proxy 'transfer stations,' native APIs, cloud platforms, and third-party aggregators used to funnel prompts to frontier models, paired with automated failover when one access route is blocked [4]. Anthropic's own telemetry ties DeepSeek, Moonshot AI, and MiniMax to more than 16 million exchanges with Claude routed through roughly 24,000 fraudulent accounts organized into what the company calls 'hydra cluster architectures,' with one proxy network alone running more than 20,000 fraudulent accounts [2][3].
MiniMax's traffic pattern illustrates the speed of the operation: 'When we released a new model during MiniMax's active campaign, they pivoted within 24 hours, redirecting nearly half their traffic to capture capabilities from our latest system,' Anthropic said, adding that MiniMax also used prompt injection against Claude Code [2]. That same tool has its own complication: in July 2026 Anthropic shipped Claude Code 2.1.197, which removed a proxy-fingerprint detection mechanism covering 147 Chinese domains, and the company has since promised a fix [9].


