Anthropic’s head of threat intelligence told CNBC that Chinese AI labs are buying dark-web access to Claude — stolen credentials and compromised accounts — to distill the company’s models without paying frontier training costs.

“There’s an entire illicit ecosystem to try to gain access to Claude and other models,” Jacob Klein said in the interview, published Sept. 3, 2026. He said companies like Moonshot AI are “spinning up tens of thousands, if not hundreds of thousands of fraudulent accounts.” CNBC reported that Klein also said Moonshot’s Kimi K3 was illegally trained off the newest version of Claude. That training claim remains Anthropic’s allegation; it has not been independently verified in court.

Distillation itself can be a legitimate technique; Anthropic’s allegation is that these campaigns used fraudulent accounts and access in violation of its terms and regional restrictions.

In a Feb. 23, 2026 disclosure, Anthropic named DeepSeek, Moonshot, and MiniMax, saying the three labs ran industrial-scale campaigns that generated more than 16 million Claude exchanges through about 24,000 fraudulent accounts. TechCrunch and The Verge reported those figures. Anthropic said the labs used commercial proxy services and “hydra cluster” networks of fake accounts across its API and third-party cloud platforms.

Anthropic has also accused Alibaba of a large distillation campaign aimed at its Qwen models. Decrypt and Financial Express, citing a letter reviewed by Reuters, reported that operators affiliated with Alibaba and its Qwen lab generated more than 28.8 million Claude exchanges between April 22 and June 5 using nearly 25,000 fraudulent accounts, according to a June letter to Senate Banking leaders.

CNBC reported that Alibaba, DeepSeek, Moonshot and MiniMax did not respond to requests for comment.

Klein framed the issue as a national-security risk if untrusted actors obtain more capable models without the original safeguards. CNBC also noted Anthropic’s private-market valuation near $1 trillion and talk of a possible October IPO — context for why the company is pressing the claim, not the lead of the story.

What remains unclear is whether Anthropic’s claims about competitors using dark-web marketplaces of stolen credit-card data and compromised AI accounts for illicit Claude access can be independently verified.