US Government Warns of Widespread Theft of AI Model Tokens by Chinese Firms
A joint advisory from top US cybersecurity and intelligence agencies has revealed a coordinated effort by six Chinese AI companies to extract billions of tokens from frontier AI models. The affected American firms include Anthropic, OpenAI, Google, and xAI, with the attackers utilizing a technique called AI model distillation to bypass security measures.
The stolen tokens are essentially the knowledge and logic contained within these advanced AI models, allowing the perpetrators to significantly reduce their own training costs and deployment timeframes. This operation is believed to be state-sponsored, with the US government assessing that the Chinese government is aware of and supporting this approach as a core development strategy for these firms.
AI model distillation is a legitimate technique used by researchers and developers to improve AI efficiency and speed up deployment. However, when misused, it can become an industrial-scale attack where attackers distribute API requests across multiple accounts, cloud services, and aggregators to bypass restrictions and detection. In this case, the Chinese firms have employed sophisticated tactics such as chain-of-thought reasoning extraction, automated failover between pathways during blocking attempts, and quality evaluation frameworks to evade defensive countermeasures.
The six Chinese AI companies implicated in this operation are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. According to the advisory, these firms have targeted various models, including Claude, GPT, Gemini, and Grok. The affected American firms have seen significant losses, with billions of tokens extracted through millions of requests.
The US government is urging AI companies to improve their detection capabilities, modify responses when distillation operations are suspected, and share intelligence about these campaigns with all stakeholders. Potential indicators of such attacks include new accounts rapidly reaching maximum usage, continuous activity without normal human idle periods, shared accounts accessed from numerous IP addresses or user agents, identical prompts across multiple providers, unusually high subscription-to-usage ratios, and coordinated switching between access routes.
As the use of AI becomes increasingly pervasive in our daily lives, the security implications of these attacks cannot be overstated. The fact that attackers can bypass security measures with relative ease highlights the need for more robust detection and prevention mechanisms. For individuals and organizations handling sensitive data or using advanced AI models, it is essential to remain vigilant and regularly review their security posture.
To protect against such attacks, users should monitor their API usage closely, implement behavioral and infrastructure-level detection, and stay informed about potential indicators of these campaigns. By working together and sharing intelligence, we can prevent the misuse of AI model distillation and mitigate the risks associated with this growing threat.
Source: Bleeping Computer — 2026-09-09