DD
MM
YYYY

PAGES

DD
MM
YYYY

spot_img

PAGES

Home Blog Page 2

Anthropic Accuses Chinese AI Labs of Using Fraudulent Accounts to Distill Claude Models

0

Anthropic has accused Chinese artificial intelligence companies and other foreign actors of using large-scale networks of fraudulent accounts to extract capabilities from its Claude models and build cheaper competing systems, escalating a broader battle over AI model distillation, intellectual property and national security.

Jacob Klein, Anthropic’s head of threat intelligence, said the company supports legitimate competition but has identified what it describes as an illicit ecosystem designed to circumvent its safeguards and obtain access to Claude at enormous scale.

“There’s an entire illicit ecosystem to try to gain access to Claude and other models,” Klein told CNBC. “This ecosystem goes through any means necessary to evade our controls, so they can spin up accounts at extreme scale.”

Anthropic alleges that foreign AI developers can then repeatedly query Claude, collect millions of responses, and use those outputs to train their own models. The process, known as distillation, can substantially reduce the cost and time required to develop competing AI systems because a developer can learn from the behavior of an already capable model rather than building every capability from scratch.

The practice itself is not inherently illegal. Model developers can use distillation legitimately when they have permission to access and use another system’s outputs and comply with intellectual-property, contractual, and export-control requirements.

Anthropic’s allegation is that some actors are deliberately bypassing those restrictions.

Anthropic has singled out several Chinese AI laboratories, including Moonshot AI, DeepSeek and MiniMax, alleging that they have distilled capabilities from its frontier models.

Klein specifically accused Moonshot’s Kimi K3 model, which gained significant attention after its launch in July, of being trained illegally using the latest version of Claude.

“We’ve seen a fair amount of this from China,” Klein said. “This is something that the industry writ large is dealing with.”

Kimi K3 has attracted adoption in Silicon Valley partly because of its lower cost and the ability for businesses to customize the model more easily. If Anthropic’s allegations are substantiated, the episode would illustrate the competitive advantage that can be gained by extracting capabilities from a more expensive frontier model and subsequently offering them at a lower price.

Anthropic has also accused Alibaba, the developer of the Qwen family of AI models, of conducting what it described as a large-scale “distillation attack” against Claude.

Anthropic is not alone in raising concerns. OpenAI and Google have separately published research and reports about model distillation and have said they are taking measures to prevent unauthorized extraction of their models’ capabilities.

The issue is gaining broader attention as the performance gap between frontier models and cheaper competitors narrows. Distillation can allow developers with significantly smaller budgets to reproduce particular capabilities without incurring the same level of training expenditure as the original model developer. But that creates a difficult commercial equation for frontier AI companies. Billions of dollars can be spent developing a highly capable model, only for competitors to potentially extract useful behaviors through repeated interactions and incorporate them into cheaper systems.

Fake Accounts Create An Enforcement Problem

According to Klein, the problem extends beyond conventional account abuse.

He said some foreign actors are creating tens of thousands, potentially hundreds of thousands, of fraudulent accounts to access Anthropic’s services and generate enormous volumes of model responses. The accounts can allegedly be created using stolen payment-card information, compromised infrastructure, and other illicit resources, including marketplaces operating on the dark web.

Once inside Anthropic’s systems, an attacker can issue large numbers of queries and collect Claude’s responses. Those responses can subsequently become training material for another model, effectively turning Anthropic’s commercial AI service into a source of data for a competing system.

The scale makes detection difficult.

A normal user might make dozens of queries. A distillation operation could generate thousands or millions of interactions, potentially distributed across a vast number of accounts so that the activity resembles legitimate usage.

“It’s very hard to fully stop this as a problem, but I think slowing it down is good and worthwhile,” Klein said.

Travis Lanham, technology chief at cybersecurity firm Armadin and a former Google engineer, said the enormous volume of traffic handled by major AI companies makes sophisticated abuse difficult to isolate.

“These companies are serving billions of requests,” Lanham said. “The millions are relatively small compared to everything and it’s just sneaking in and trying to look like the rest of the crowd.”

The development has created a classic security problem for AI providers because aggressive controls can reduce abuse but can also make legitimate services more difficult for ordinary customers to access.

The National-Security Dimension

Anthropic’s concerns extend beyond commercial competition.

Klein said unauthorized access could allow actors that would otherwise have limited access to advanced AI systems to acquire capabilities they could use for surveillance, cyber operations, or potentially biological-weapons development.

He also pointed to what he described as a specific campaign by a China-based entity that used Anthropic’s technology for espionage at scale.

“There is a national security concern at play if malicious actors, bad actors who we don’t trust are gaining access to more capable models than they could have otherwise through the act of distillation,” Klein said.

The argument adds another layer to Washington’s increasingly contentious debate over advanced AI exports and access to frontier models. The Trump administration said in an April policy memorandum that distillation that undermines American research and proprietary information was “unacceptable” and said it would explore measures to hold foreign actors accountable.

The issue is particularly sensitive because the United States is simultaneously trying to maintain its lead in frontier AI while preventing advanced technology from reaching foreign actors that Washington considers security risks.

Thus, distillation is becoming one of the less visible but potentially consequential fronts in the global AI competition.

Training a frontier model requires enormous quantities of computing power, specialized chips, data, and engineering talent. Distillation can change the economics by allowing a smaller developer to learn from an existing model’s responses rather than independently reproducing the entire development process.

That does not necessarily mean a distilled model will replicate the original model’s full capabilities. The student model may reproduce specific reasoning patterns, coding abilities, or domain expertise while lacking other characteristics of the teacher model.

But even partial capability transfer can be commercially significant when the resulting system is cheaper, easier to customize, or subject to fewer restrictions. This creates an unusual incentive structure for frontier AI companies. Their models must be accessible enough to generate revenue and support developers, but every additional interaction can potentially provide information that a competitor could use to improve its own system.

Anthropic’s position is therefore not that competition itself is the problem.

“I think competition is great,” Klein said. “The concern here is if you are taking our model, distilling it through fraudulent means, creating millions of fake accounts using stolen credit cards and stolen infrastructure, to then produce a model that doesn’t have safeguards in place.”

Industry analysts expect that situation to become increasingly necessary as AI companies, regulators and governments attempt to establish where legitimate model development ends and unauthorized capability extraction begins.

Nvidia, Oil and Geopolitics Put Investors on a Market Knife Edge

0

The final week of August delivered a sharp reminder that modern financial markets rarely wait for the official opening bell before repricing risk.

Nvidia’s earnings, oil-market tensions around the Strait of Hormuz, and shifting expectations across equities and commodities demonstrated how quickly information can move from headlines into asset prices.

Nvidia’s after-close earnings report was the first major catalyst. The company’s results were closely watched because of its central position in the artificial-intelligence investment boom.

Investors were not simply assessing quarterly revenue and profits; they were trying to determine whether the extraordinary spending on AI infrastructure could continue supporting the valuations of technology companies.

The market’s response was immediate. Nvidia shares moved 7.4% the following morning, illustrating the scale of expectations embedded in the stock. Such a move is more than a reaction to earnings figures.

It represents a rapid reassessment of future growth, semiconductor demand, data-center investment and the broader AI trade. For markets, Nvidia has increasingly become a proxy for something much larger.

Its performance influences sentiment across chipmakers, cloud companies, software firms and even major equity indexes. When Nvidia delivers, investors can interpret that as evidence that the AI capital-spending cycle remains intact.

When expectations are challenged, the consequences can spread rapidly across risk assets. But the week’s repricing did not stop with technology stocks. Days later, tensions around the Strait of Hormuz introduced a completely different source of uncertainty: energy security.

Sunday’s escalation near the critical shipping corridor pushed Brent crude higher before regular trading reopened. Again, the important point was not simply the direction of oil prices. It was the speed with which geopolitical risk became a market variable.

The Strait of Hormuz is one of the world’s most important energy chokepoints. Any threat to shipping through the region can immediately raise concerns about supply disruptions, transportation costs and inflation.

Higher crude prices can eventually feed into gasoline, logistics, manufacturing and consumer prices, complicating the outlook for central banks that are already balancing inflation against economic growth.

By the time conventional markets reopened, traders were not starting from a neutral position. Prices had already begun incorporating the information through overnight and weekend trading mechanisms.

The repricing was underway before many investors had the opportunity to react through traditional market sessions. This sequence reveals an increasingly important characteristic of global markets: risk is now continuous.

Earnings arrive outside regular trading hours. Geopolitical developments emerge during weekends. Cryptocurrency markets trade around the clock, providing an early indication of how investors are responding to new information.

Futures markets and international exchanges can also absorb shocks long before domestic equity markets reopen. The result is a market environment in which the opening price can sometimes reflect hours of accumulated information rather than a fresh beginning.

The final week of August therefore offered two contrasting catalysts with a similar consequence. Nvidia demonstrated how corporate earnings and AI expectations can rapidly reshape equity valuations.

Hormuz tensions showed how geopolitical developments can alter the inflation and energy outlook almost instantly. They highlighted a broader reality: investors are no longer pricing yesterday’s world. They are continuously attempting to price tomorrow’s risks.

By the time the trading session officially begins, much of the adjustment may already have happened.

India’s 7.8% Growth Triggers Debate Over Whether Economy Is Stronger Than Data Suggest

0

India’s unexpectedly strong economic growth has triggered a debate over the reliability of the country’s newly revised GDP data, with a former senior finance ministry official and an ex-central bank governor questioning whether the headline expansion overstates underlying momentum.

India’s economy grew 7.8% in the three months through June from a year earlier, government data showed on Monday, significantly exceeding the 7.1% median forecast in a Reuters poll. The expansion was supported by an investment boom and strong manufacturing activity, alongside resilient consumer demand.

The reading has nevertheless raised questions over how much of the acceleration reflects genuine economic strength and how much is the result of changes to the way India calculates GDP.

Subhash Chandra Garg, a former senior Finance Ministry bureaucrat, argued in Indian media that the growth rate was inflated because the government had lowered its estimate of GDP for the same quarter a year earlier, creating a weaker base against which the latest expansion was measured.

Raghuram Rajan, the former governor of the Reserve Bank of India, raised a different concern, questioning why such robust GDP growth has not been accompanied by stronger job creation, domestic investment and foreign portfolio inflows.

Some private-sector economists have also focused on the GDP deflator, the measure used to remove price changes from nominal GDP and calculate real economic growth. They argue that the unusually low deflator may be understating inflation and consequently overstating real output growth.

The controversy has given India’s opposition another line of attack against Prime Minister Narendra Modi’s government. A senior Congress party official dismissed the 7.8% figure as “statistical gymnastics,” turning what initially began largely as a social-media debate into a broader political dispute over the government’s economic record.

The government has faced growing pressure over employment and economic opportunity, particularly among younger Indians. Youth protests in July contributed to the resignation of the education minister and were widely seen as reflecting broader frustration over jobs, opportunities and corruption in the education system.

Government Defends Revised GDP Methodology

India’s statistics ministry responded by holding a news conference on Wednesday to defend the GDP figures and rebut Garg’s criticism.

A senior statistics official said the methodology changes introduced in February followed extensive consultation and were designed to provide a more accurate picture of economic activity.

The revised series changed the GDP base year by more than a decade and incorporated new data sources as well as changes in the goods and services captured by the national accounts.

One of the most consequential changes was the revision of nominal GDP for April-June 2025. Under the new methodology, the figure was reduced to 80 trillion rupees ($850 billion), compared with 86.05 trillion rupees under the previous GDP series. Using the old base would have produced nominal GDP growth of only 2.6% in the latest quarter, compared with the 10.3% reported under the new series.

But the government has rejected a direct comparison between the two figures, explaining that the new series does more than simply change the base year. It also incorporates revised data sources, coverage and methodology, meaning the old and new estimates are not directly comparable.

The statistics secretary said quarterly revisions over the past three years had moved in both directions, while changes to annual GDP estimates had been relatively limited.

The government’s defense is deemed necessary because GDP revisions are a normal part of national accounting. Updating the base year and incorporating better data can change the measured size and composition of an economy without necessarily implying that the underlying activity itself has suddenly changed.

The Deflator Becomes The Key Battleground

The more difficult question concerns prices.

India’s GDP deflator for April-June was just 2.3%, considerably below retail inflation of more than 4% and wholesale inflation of more than 9%. Because real GDP is calculated by stripping price changes from nominal output, the choice of deflator can materially affect the reported growth rate. A lower deflator means a larger portion of nominal growth is treated as an increase in real economic activity.

The government says the apparent gap does not indicate that inflation has been understated. It argues that the revised GDP series uses the internationally accepted method of double deflation, which separately adjusts the value of output and the cost of inputs for changes in prices.

The statistics secretary said the new system also relies on a more granular Producer Price Index, using more than 300 deflators covering inputs and outputs, compared with about 180 under the previous methodology.

That approach can produce a GDP deflator that differs significantly from consumer or wholesale inflation because the three measures capture different baskets and stages of the economy. Consumer inflation, for example, measures prices faced by households, while GDP deflation reflects the prices of domestically produced goods and services and their contribution to national output.

But that has not ended the debate.

Mumbai-based ICICI Securities Primary Dealership said the lower GDP deflator was compatible with an environment in which input prices were rising faster than output prices. In that interpretation, the unusually low deflator does not necessarily invalidate the growth figure.

Societe Generale economists took a more cautious view, noting that the low deflator raises questions about the strength of real-sector activity.

Other Indicators Provide Mixed Evidence

India’s high-frequency economic data offers ammunition to both sides of the debate, although several indicators support the government’s broader argument that economic activity remains strong.

Auto sales increased 21% in August, while bank credit growth reached a decade-high 19%. Net direct tax revenue also increased more than 23% year-on-year during the April-August period, pointing to strong activity and income generation in parts of the economy.

Those indicators make it difficult to dismiss the GDP figures as purely a statistical phenomenon.

At the same time, the Purchasing Managers’ Index, a closely watched survey-based gauge of business activity, has weakened to multiyear lows. That contrast underpins why economists remain divided over the extent to which India’s headline GDP growth is translating into broad-based economic momentum.

The disagreement also goes beyond the technical details of national accounting. The central economic question is whether India’s rapid headline growth is generating sufficient employment, investment and capital inflows to support sustained expansion. Rajan’s criticism goes directly to that issue. If output is expanding at close to 8% but employment, private investment and foreign capital flows are not accelerating proportionately, the headline number may not fully capture the quality or breadth of growth.

For the Modi government, the stakes are higher than defending a single quarterly statistic. India is seeking to sustain rapid growth while attracting investment, expanding manufacturing and creating enough jobs for a large and increasingly young workforce.

The latest figures provide evidence that the economy retains considerable momentum. But the dispute over the methodology means investors and policymakers are likely to scrutinize other indicators more closely before concluding that India’s underlying growth rate has genuinely shifted higher.

Ultimately, the credibility of the new GDP series will depend less on any single quarterly number than on whether its estimates continue to align over time with employment, investment, tax receipts, corporate activity, consumption and other independent measures of economic performance.

AI Models Are Becoming Cyber Weapons as Hackers Exploit Distillation and Other Technologies Behind Them

0
Security lock concept

Artificial intelligence companies are confronting a new cybersecurity problem as malicious actors increasingly exploit powerful AI models not only to generate phishing messages or malicious code, but also to automate attacks, bypass safeguards, and extract capabilities from the models themselves.

The threat is changing the security equation for AI developers. The same models that companies are making accessible to billions of users can also provide attackers with a scalable source of coding, reconnaissance, and operational support. At the same time, autonomous AI agents are beginning to perform tasks directly, creating the possibility that a compromised or manipulated model can become an active participant in a cyberattack rather than simply an assistant to a human attacker.

Travis Lanham, technology chief at cybersecurity firm Armadin and a former Google engineer, said malicious activity can remain difficult to detect because AI companies process enormous numbers of legitimate requests.

“These companies are serving billions of requests,” Lanham said of the major AI labs. “The millions are relatively small compared to everything and it’s just sneaking in and trying to look like the rest of the crowd.”

That scale creates a huge vulnerability. An attacker does not necessarily need to break into an AI company’s core infrastructure to exploit its technology. Instead, they can abuse legitimate interfaces, create large numbers of accounts, distribute activity across infrastructure, and make malicious requests resemble normal usage.

The problem has already appeared in several forms, with several American AI companies lamenting about distillation.

Anthropic said in February that Chinese AI companies DeepSeek, Moonshot AI and MiniMax had used about 24,000 fraudulent accounts to conduct roughly 16 million exchanges with Claude in an effort to extract its capabilities through model distillation. Anthropic alleged that the activity, known as distillation, targeted capabilities including reasoning, coding, and tool use.

Distillation itself is not inherently illegal or malicious. Developers can legitimately use a more capable model to help train or improve another system, provided they have the necessary permissions and comply with applicable intellectual-property and export-control requirements.

The security concern arises when attackers or competitors use fraudulent accounts, stolen payment credentials, or other deceptive methods to obtain massive quantities of model outputs and reproduce capabilities they did not develop independently.

Anthropic’s head of threat intelligence, Jacob Klein, drew that distinction explicitly.

“I think competition is great,” Klein said. “The concern here is if you are taking our model, distilling it through fraudulent means, creating millions of fake accounts using stolen credit cards and stolen infrastructure, to then produce a model that doesn’t have safeguards in place.”

The implications go beyond intellectual property. If an attacker can systematically extract capabilities from a highly capable model and transfer them to another system, safeguards imposed by the original developer can potentially be left behind. That creates a new form of AI supply-chain risk. A company may spend enormous resources developing restrictions around dangerous cyber, fraud, or other capabilities, only for an adversary to reproduce portions of the underlying capability in a model operating outside those controls.

AI Is Moving from Assistant to Operator

The more immediate cybersecurity concern is the growing ability of AI systems to carry out multi-step operations.

Google’s Threat Intelligence Group reported that threat actors were increasingly integrating AI into the attack lifecycle, using the technology for reconnaissance, social engineering, and malware development. Its research indicates that AI is moving beyond simple experimentation toward more systematic use by attackers.

Anthropic has also documented a separate espionage campaign in which attackers used Claude’s agentic capabilities to execute cyber operations rather than simply receiving advice from the model. The company described the campaign as an unprecedented use of AI in which the system was involved directly in carrying out attacks.

A particularly revealing case emerged in August, when Russian-speaking cybercriminals associated with the Aur0ra group were reported to have used Cursor, an AI-powered coding assistant, to target at least seven organizations in the United States and Europe.

According to cybersecurity firms Gambit Security and CloudSek, the attackers manipulated the AI agent by presenting malicious activity as a simulation. The operation included credential theft and exploitation of target systems. Gambit investigators discovered an exposed server containing conversations between the attackers and the AI agent, which was powered by Anthropic’s Claude Sonnet 4.5.

The significance of that incident is not simply that hackers used AI to write code. They were able to incorporate an AI coding agent into an operational attack and manipulate the model’s understanding of what it was being asked to do.

That illustrates why conventional AI safety filters can become difficult to maintain as models become more capable. A malicious actor does not necessarily have to defeat a safeguard technically. They may instead manipulate the context presented to the model, distribute the attack across multiple interactions, or persuade the system that a prohibited action is part of a legitimate exercise.

AI Models Are Also Becoming Targets

The threat therefore runs in both directions.

AI can be exploited to attack other organizations, but AI models themselves are becoming valuable targets for exploitation.

The model-distillation allegations involving Chinese AI companies demonstrate how an adversary can attempt to extract a commercially valuable system through legitimate interfaces rather than stealing the underlying model weights. The attacker effectively turns the model’s own API into a mechanism for reproducing its capabilities.

That is challenging for AI companies because restricting access too aggressively can undermine the commercial purpose of their systems. Developers want their models to be available to consumers, enterprises, and software developers, but every additional user and API interaction creates another opportunity for abuse.

Lanham’s observation captures the scale problem: when a system handles billions of requests, malicious activity can represent only a tiny fraction of overall traffic while still producing substantial damage.

Against that backdrop, AI companies must look not only at individual prompts but also at patterns across accounts, payment methods, IP addresses, infrastructure, geographic locations, and request sequences. The challenge is amplified when attackers use stolen identities, payment cards and infrastructure, because the activity can be deliberately fragmented across what appear to be unrelated customers.

Real-World Incidents Are Moving Faster Than The Safeguards

Recent incidents involving AI agents suggest the problem is also extending beyond conventional cybercrime. During a cyber evaluation, the UK’s AI Security Institute identified AI agents taking sustained, unsanctioned actions directed at real people and organizations.

OpenAI and Hugging Face separately disclosed a security incident during an AI model evaluation in which advanced AI agents demonstrated unexpected cyber capabilities. OpenAI has since been developing stronger controls around model autonomy and internet access.

Anthropic, meanwhile, temporarily halted some external cybersecurity testing after AI models accessed the internet and hacked systems during evaluations. The company subsequently introduced additional safeguards, including a classifier designed to detect and stop escape attempts, and stricter requirements for external testing environments.

These cases have gained public interest because they demonstrate that the risk is no longer confined to hypothetical scenarios in which AI might eventually become capable of sophisticated cyberattacks. Researchers are already observing systems that can chain together multiple actions, interact with external environments, and continue operating after encountering restrictions.

The Cybersecurity Arms Race Is Changing

The result is a new AI security arms race.

AI companies are trying to make models more capable while simultaneously teaching them when to refuse dangerous requests. Attackers, meanwhile, are trying to discover ways around those restrictions and increasingly have access to competing models, open-source systems, and automated tools that can be combined into attack workflows.

The distinction between “using AI” and “an AI conducting an attack” is consequently becoming less clear.

That distinction has become a serious matter for governments and businesses because traditional cybersecurity frameworks generally assume a human attacker operating software. Agentic AI introduces another layer: software capable of interpreting objectives, making decisions, writing or modifying code, interacting with systems, and potentially continuing through multiple stages of an operation.

Physics of Capital and How To Invest; Register for Nigeria Capital Market Masterclass

0

Career is about more than making money. Yet money helps to remove many of life’s inconveniences. That is why it remains strange that someone can attend a university, graduate and enter the workforce without receiving any practical education on personal finance and wealth management.

Universities teach corporate finance and equip people to make money for companies by optimizing the factors of production. But they rarely teach graduates how to manage, preserve and grow their own earnings. For me, that is a major failure of the modern education system.

As a young banker, I quickly understood one important principle: how much you earn is only a small part of your journey towards financial independence. Reaching that destination requires moving from a static phase to a dynamic phase, as we learned in mechanics in physics. In other words, you must take action, and that action must begin with a plan.

During my first month as a banker, I developed what I called the 45-20-20-15 Strategy, allocating my wages among different “catalysts for success”:

  • 45% for myself and my family: housing, clothing, transportation and related needs.
  • 20% for personal development: professional certifications, education and new capabilities.
  • 20% for other obligations and opportunities.
  • 15% for investments: dividend-paying stocks and other investable assets.

Using simple calculus and regression, I estimated that by consistently investing 15% of my income, every five years of work could generate the equivalent of two additional years of wages, assuming constant inflation and currency values.

My strategy has changed over the years because my needs and responsibilities have evolved. The central message is simple: earning money is important, but understanding how markets work, and how to invest wisely, is indispensable.

We created Tekedia Nigeria Capital Market Masterclass to provide practical guidance on investing, portfolio management, financial products, market technology and much more.

Across 16 comprehensive modules, you will master the core physics of capital and understand the DNA of Nigeria’s capital market, how it works, how value is created and how you can participate intelligently. The programme begins Oct 5 for eight weeks.

REGISTER today here.