I’ve had a theory for a while based on my own experience and the influx of posts from Claude/Claude Code users wondering why their session/weekly usage is suddenly getting burned through absurdly quickly. After reading Anthropic’s reports on DeepSeek and Moonshot ( https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks ), I think it’s worth seriously investigating. Anthropic says: “These labs generated over 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.” And describes proxy services running: “sprawling networks of fraudulent accounts that distribute traffic across our API as well as third-party cloud platforms.” Most interestingly: “a single proxy network managed more than 20,000 fraudulent accounts simultaneously, mixing distillation traffic with unrelated customer requests to make detection harder.” Anthropic also found DeepSeek generating “synchronized traffic across accounts,” with patterns suggesting “load balancing” to increase throughput, improve reliability, and avoid detection. Here’s my theory: What if some of those credentials/accounts weren’t simply fake accounts, but compromised legitimate Claude accounts? An attacker could potentially wait until a legitimate user is actively using Claude and run additional distillation queries through their authenticated access, making the activity blend into real usage while chewing through that person’s session/weekly limits. That would leave the user wondering why they suddenly hit their limit despite seemingly doing the same amount of work as before. I experienced exactly that kind of unexplained usage behavior myself, and I’ve seen a huge influx of similar complaints. My second theory is even more interesting. I wonder whether compromised users could sometimes have their Claude Code requests routed to DeepSeek/Kimi while their actual Claude access was being consumed elsewhere for distillation or serving other customers. That could potentially explain reports where Claude Code suddenly feels completely different - different lexicon, noticeably worse output, strange behavior, or occasionally unexpected Chinese characters - despite appearing to still be Claude Code. We now know from Anthropic’s investigation that these companies were willing to build sophisticated proxy infrastructure around Claude, distribute extraction across thousands of accounts, and deliberately mix distillation traffic with legitimate customer traffic. To be clear: Anthropic has NOT said that legitimate Claude accounts were stolen and used this way. That is my theory. But given what they’ve now uncovered, I think Anthropic should answer a very simple question: Were all ~24,000 “fraudulent accounts” created by these operations, or did Anthropic find compromised credentials belonging to previously legitimate Claude users among them? Because if the latter happened, it could potentially explain something a lot of Claude users have been complaining about for months. attacks submitted by /u/LiquidVolatility
Originally posted by u/LiquidVolatility on r/ClaudeCode
