White House official accuses China of stealing Anthropic model for K3 development

A senior US official publicly alleges state-sponsored model theft involving distillation attacks and offshore infrastructure, escalating AI geopolitical tensions.

Abstract illustration representing cross-border data infrastructure and model distillation
AI-generated illustration · Sylvaris

White House alleges model theft via distillation

A senior White House official has publicly accused China of stealing Anthropic's proprietary AI model to develop its K3 system. The allegation centers on distillation attacks—a technique where a less capable model is trained by repeatedly querying a more advanced one to replicate its behavior.

The official specifically pointed to Thailand as hosting hardware infrastructure that may have facilitated these distillation operations. This represents one of the first times a US administration has publicly attributed model theft to a specific nation-state actor with technical detail.

Distillation attacks exploit API access

Distillation attacks work by sending thousands or millions of prompts to a target model through its API, then training a new model on the input-output pairs. The technique can replicate much of a model's capabilities without accessing its weights or training data.

These attacks are difficult to detect and prevent, as they appear as legitimate API usage. Model providers typically implement rate limits and usage monitoring, but sophisticated attackers can distribute queries across multiple accounts and jurisdictions to avoid detection.

Offshore infrastructure complicates attribution

The White House's specific mention of Thailand-hosted hardware highlights how attackers use third-country infrastructure to mask their operations. Hosting compute resources outside both the target's jurisdiction and the attacker's home country creates legal and technical barriers to investigation.

This case may prompt stricter API access controls and international cooperation on AI model protection. Several countries are already exploring export controls on model weights and API access for frontier systems, treating them as dual-use technologies similar to encryption tools.

sources
more in Security
Social engineering attack bypasses physical security, grants unauthorized access to medical records Physical security controls remain vulnerable to social engineering tactics that exploit human trust rather than technical systems. Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations.