Anthropic says two prominent Chinese AI labs did more than query Claude to copy its capabilities. Moonshot AI and DeepSeek allegedly routed live customer prompts to Claude through fraudulent accounts, returned some of Claude’s answers under their own services, and retained exchanges to help train competing models.
The claims appear in Anthropic’s September 2026 threat intelligence report, published on September 10. In one ten-day period, Moonshot allegedly forwarded almost 300,000 customer requests, mostly to Claude Opus. The disclosed prompts included surveillance data, corporate source code, internal documents, and active credentials for government and commercial systems.
These remain Anthropic’s allegations. The public report does not provide raw traffic logs or an independent forensic audit that outsiders could use to reproduce its attribution. Even with that limitation, the findings identify a serious AI security problem: users may not know which company or model is processing the information they enter.
Kimi and DeepSeek Allegedly Became Claude Front Ends
Model distillation usually involves a capable “teacher” model generating examples that train a smaller “student” model. Companies routinely distill their own models or use another provider’s outputs under an agreement.
Anthropic uses the term illicit distillation for coordinated, unauthorized campaigns that use fraudulent accounts, stolen payment methods, compromised API keys, and proxy infrastructure to extract Claude’s capabilities. The company first accused DeepSeek, Moonshot, and MiniMax of industrial-scale distillation in February 2026, when it said the three labs generated more than 16 million exchanges through approximately 24,000 fraudulent accounts.
The latest report adds a more troubling detail. Anthropic alleges that Moonshot did not always process Kimi users’ requests with a Kimi model. Instead, its system silently forwarded selected prompts to Claude and displayed Claude’s responses as if they came from Kimi.
Moonshot allegedly relayed nearly 300,000 customer requests during one ten-day period. Most went to Opus through a proxy network containing 5,380 fraudulent accounts, primarily appearing to operate from Singapore and Japan. Anthropic says Moonshot also captured at least some of these exchanges and built a pipeline for extracting Claude’s reasoning traces.
DeepSeek allegedly ran a similar operation. Its systems inspected strings inside incoming requests to identify people using DeepSeek models through Claude Code, the Claude Agent SDK, OpenCode, and other coding harnesses. Some tagged requests were then redirected to Claude Opus without the customer’s knowledge.
That routing meant a developer could select DeepSeek as the model inside a coding tool, send repository context or credentials, and unknowingly have the request processed by Anthropic’s infrastructure.
The Relayed Prompts Included Surveillance and Credentials
The most serious part of Anthropic’s report is not the potential copying of Claude. It is the sensitive customer information that allegedly crossed an undisclosed trust boundary.
Anthropic describes a Moonshot user it assessed as likely affiliated with China’s People’s Liberation Army. The user loaded CCTV archive data concerning one targeted person and asked what they believed was Kimi to determine whether the individual was behaving abnormally.
The surveillance material drew on hundreds of cameras in Chengdu. The locations included cameras outside PLA facilities, institutes associated with China Electronics Technology Group Corporation, and a major state-owned enterprise. Moonshot allegedly forwarded the request and data to Claude.
In another Moonshot case, an engineer building an internal system for a Chinese state-owned enterprise submitted source code and active credentials belonging to several major Chinese companies. Anthropic says the engineer had no way to know that Claude was receiving the information.
The DeepSeek examples were similarly sensitive:
- An employee at a Chinese technology company submitted internal documentation containing the specifications, organizational structure, and strategic objectives of a flagship AI program.
- An IT operator handling data from a Russian government agency associated with the Russian Ministry of Defense exposed live credentials for a government database.
- Engineers working on a case-management system for a municipal Chinese Public Security Bureau shared details of a tool that compared an individual’s movements with police records using citizens’ national identification numbers.
Anthropic clearly received and processed these requests, and its investigators accessed enough information to describe them. That does not establish that every affected prompt remains stored today.
Anthropic’s published API retention policy says standard inputs and outputs are normally deleted from its back end within 30 days. Exceptions apply when content must be kept to investigate policy violations or satisfy legal obligations. Inputs and outputs associated with detected violations can be retained for up to two years.
The accurate conclusion is therefore that the customer data was exposed to Anthropic, not that Anthropic necessarily retains every exchange indefinitely. The report does not disclose the current retention status of the individual prompts it describes.
How Customer Traffic Became Training Data
The alleged relay system served two purposes. It could give users an answer from a stronger model, while also creating valuable training examples for the Chinese lab operating the service.
Each relayed session contained several useful components:
- A real user request, often based on a practical problem
- Claude’s response to that request
- Tool calls and multi-step agent behavior
- Feedback implied by subsequent user messages
- Potentially, a reconstruction of Claude’s hidden reasoning
Real customer sessions can be more valuable than synthetic prompts because they reflect actual coding environments, documents, errors, credentials, and workflows. They also cover unusual tasks that a lab may not think to create internally.
Anthropic says Claude normally returns a “thinking signature,” a reference that supports continued reasoning without exposing the complete internal trace. Moonshot and DeepSeek allegedly saved these signatures, opened new sessions, and persuaded Claude to reconstruct the underlying reasoning. Anthropic calls this technique a cross-session replay attack.
The resulting chain-of-thought transcripts could then be cleaned and converted into supervised fine-tuning data or used in reinforcement-learning pipelines. Rather than copying only a final answer, the labs were allegedly attempting to capture how Claude decomposed and solved complex tasks.
Anthropic says it has since introduced additional controls to make those attacks less effective. Its newer protections summarize internal reasoning, restrict modifications to earlier conversation context, detect coordinated extraction patterns, and require identity verification when accounts show signs of unauthorized resale or access from unsupported countries.
Alibaba’s Campaign Was Far Larger
DeepSeek and Moonshot are only two of the seven China-based laboratories named in the report. Anthropic also attributes campaigns to Alibaba, Zhipu AI, Xiaomi, SenseTime, and MiniMax.
The reported numbers cover different periods and tactics, so they should not be treated as a direct performance comparison.
| Chinese AI lab | Scale reported by Anthropic | Alleged method |
|---|---|---|
| Alibaba, Qwen/Tongyi Lab | More than 151 million exchanges between May and July 2026 | Extracted Opus 4.6 and 4.7 reasoning for Qwen training and internal AI research |
| Moonshot AI | More than 23 million exchanges between May and July | Relayed some Kimi customer requests to Claude and collected reasoning traces |
| DeepSeek | More than 12.1 million exchanges over 14 days in July | Rerouted selected user and coding-tool requests to Opus |
| Zhipu AI, also known as Z.ai | More than 3.4 million exchanges over 17 days in June and July | Replayed and cleaned Claude reasoning for GLM training |
| Xiaomi | More than 400,000 exchanges over 20 days in March and April | Replayed MiMo user conversations and coding sessions through Claude |
| SenseTime | No total disclosed | Purchased user-Claude transcripts from third-party data vendors |
| MiniMax | No total disclosed | Allegedly operated a shell proxy service to collect exchanges with US models |
Alibaba’s campaign was the largest Anthropic says it has measured. It allegedly peaked at nearly three million exchanges per day from more than 3,500 fraudulent accounts. A first pool of almost 5,000 accounts used residential proxies, disposable email addresses, and virtual payment cards. When Anthropic blocked it, the operators shifted traffic to another pool.
Anthropic says the resulting reasoning transcripts were converted into supervised fine-tuning data used to improve Qwen 3.5, 3.6, and 3.7. The requests focused on software engineering, kernel development, agentic work, and long-horizon tasks.
Not every lab allegedly returned Claude’s answers directly to users. Anthropic says Xiaomi replayed previously captured customer sessions but did not appear to serve Claude responses back to those customers. SenseTime allegedly acquired transcripts from third-party vendors, while MiniMax reportedly created a proxy service through a shell company.
The Evidence Comes From the Alleged Victim
Anthropic says it attributed the campaigns with high confidence, but the public material remains a selected account written by the company whose models were targeted. It does not reveal the account identifiers, payment records, network logs, or complete technical indicators behind each attribution.
There are legitimate reasons to withhold that information. Publishing it could expose affected customers, disclose credentials, or teach operators how to avoid detection. It also means the most explosive details cannot yet be independently validated from the report alone.
China’s Ministry of Commerce rejected broader US allegations about industrial-scale AI distillation on September 9, one day before Anthropic published these customer-routing examples. The ministry described distillation as a neutral and widely used technique and said claims of malicious Chinese activity lacked a factual and legal basis.
That response addressed an earlier US government advisory rather than the specific CCTV, corporate-data, and Russian-database cases disclosed on September 10. The named companies have not provided detailed public explanations addressing Anthropic’s individual examples.
Distillation itself is not proof of wrongdoing. The central allegations involve the surrounding conduct: false accounts, stolen credentials, regional-access evasion, undisclosed model substitution, and the use of customer sessions for training.
AI Customers Need to Verify Who Processes Their Data
Organizations can no longer treat a model name in an interface or configuration file as proof of which system receives their information. AI applications increasingly use gateways, fallback providers, proxy APIs, and dynamic model routers. Each additional layer creates another place where prompts can be logged, replayed, or redirected.
DeepSeek or Kimi users who entered active secrets should respond as they would to any possible third-party disclosure:
- Revoke and rotate database passwords, API keys, bot tokens, cloud credentials, and integration secrets.
- Review authentication logs for access from unexpected locations, devices, or services.
- Identify source code, internal documents, personal information, or government data submitted through the affected services.
- Check whether third-party coding tools or model routers stored their own copies of the sessions.
- Replace long-lived credentials in development environments with short-lived, narrowly scoped tokens.
Companies procuring AI services should also require written disclosure of every upstream model provider, fallback service, geographic processing location, retention period, and training policy. Contracts should prohibit silent provider substitution when prompts may contain regulated, confidential, or security-sensitive data.
Anthropic’s report does not provide an exposure checker, a list of affected accounts, or a method for determining whether a particular conversation was forwarded. Until the accused labs disclose more, customers have to make risk decisions without knowing the exact scope.
Final Thoughts
The report turns model provenance into a security control rather than a branding detail. A user who selects DeepSeek or Kimi is making assumptions about where the prompt goes, which company can read it, and which privacy rules apply. Secretly substituting Claude would invalidate all three assumptions.
Anthropic’s attribution deserves independent scrutiny, particularly given the geopolitical and commercial stakes. The disclosed examples are still specific enough to justify immediate action from AI providers. Users should be told when requests leave a service, when another company’s model generates the answer, and when conversations can become training data. Without those disclosures, an AI privacy policy cannot describe the real data path.
Frequently Asked Questions
5 questions
1Did DeepSeek and Kimi really send customer prompts to Claude?
Anthropic says both services secretly sent selected customer prompts to Claude, but the allegations have not been independently audited. Its September 10, 2026 report says Moonshot displayed Claude responses as Kimi answers, while DeepSeek identified certain coding-tool users and redirected their requests to Opus. The public evidence does not include the complete network logs or account records behind those conclusions.
2
Sources
- Anthropic’s September 2026 threat intelligence reportwww-cdn.anthropic.com
- https://x.com/IntCyberDigest/status/2098149671957103005x.com
- first accused DeepSeek, Moonshot, and MiniMax of industrial-scale distillationanthropic.com
- published API retention policyprivacy.anthropic.com
- rejected broader US allegations about industrial-scale AI distillationapnews.com
