Anthropic Accuses Moonshot and DeepSeek of Secretly Routing Users to Claude
A.I. / news
Anthropic Accuses Moonshot and DeepSeek of Secretly Routing Users to Claude
Moonshot alone relayed more than 23 million exchanges to Claude between May and July using thousands of accounts made to look Singaporean and Japanese, Anthropic said Thursday.
Anthropic said Thursday that Moonshot AI and DeepSeek secretly routed live customer requests to Claude models and showed users the responses as if they came from their own systems, then used the resulting transcripts to train their own software.
The claim is in Anthropic's "Detecting and countering misuse of AI: September 2026" report, published Sept. 10 and covering activity the company disrupted between December 2025 and August 2026. Jacob Klein, Anthropic's head of threat intelligence, told The Wall Street Journal that Kimi users "had no way of knowing that their Kimi activity was being passed to Claude," and that the practice would be "a major scandal" if a U.S. company had done it, according to Seoul Economic Daily's account of the interview.
Moonshot moved 23 million exchanges through fake accounts
Anthropic said Moonshot's Kimi service diverted close to 300,000 customer requests to Claude over a single 10-day window, with most of that traffic going to Opus, Anthropic's most capable model. Between May and July, the company said, Moonshot's total traffic to Claude topped 23 million exchanges, routed through more than 5,380 accounts built to appear as though they were based in Singapore and Japan, since Anthropic does not permit access to Claude from inside China.
DeepSeek moved 12.1 million exchanges in two weeks
DeepSeek ran a similar operation, Anthropic said: more than 12.1 million exchanges relayed to Claude over a 14-day window in July. The South China Morning Post reported that Anthropic called this the first time it has accused Chinese labs of rerouting paying users directly into Claude, rather than simply querying the API to harvest training data.
Alibaba ran the largest operation, without rerouting users
The same report names Alibaba as responsible for the largest distillation case Anthropic says it has measured: more than 151 million Claude exchanges between May and July, run through upwards of 3,500 fraudulent accounts and peaking at 3 million daily interactions. Unlike Moonshot and DeepSeek, Anthropic said, Alibaba's traffic came from direct API queries rather than rerouted customer sessions.
Anthropic described the intermediaries behind all three operations as "transfer stations," services operating outside China that opened accounts with fake identities, stolen or forged credit cards and stolen API keys.
| Company | Exchanges | Window | Method |
|---|---|---|---|
| Alibaba | 151 million+ | May-July 2026 | Direct API queries |
| Moonshot | 23 million+ | May-July 2026 | Rerouted live user sessions |
| DeepSeek | 12.1 million+ | 14 days, July 2026 | Rerouted live user sessions |
What Anthropic has not confirmed
Anthropic said the rerouted sessions carried "sensitive information, including from individual users, major multinational companies, and state-affiliated actors," and called the practice "likely inconsistent with privacy laws and the labs' own terms of service," according to a summary of the report. The company did not say what share of Moonshot's or DeepSeek's total traffic went to Claude, or whether either lab had told its users their prompts were leaving the country. Neither Moonshot nor DeepSeek had issued a public response as of Friday.
The rerouting tactic is distinct from the more general distillation practice the Cybersecurity and Infrastructure Security Agency warned about separately in its own advisory this same week. Anthropic's threat intelligence team disclosed a second, unrelated case in the same report involving computer science undergraduates who built an exploit pipeline on Claude.
Sources
More in A.I.
- 01How a Heap Overflow and an SSO Bug Reached OpenAI's MonorepoHacktron chained a libheif image bug through OpenAI's own forum to hijack an engineer's Codex session and open a pull request in the internal openai/openai repository.
- 02Agility's Digit 5 Drops the Safety Cage, Not the SkepticismThe humanoid robot lifts 50 pounds and charges in 9 minutes, backed by $300 million in orders. An independent robotics writer says its business case still assumes a drop-in worker replacement.
- 03PrismML Shrinks a 27B Model to 5.9GB at 1.72 BitsTernary Bonsai 2 27B keeps 98.2% of its full-precision score by rebuilding Qwen3.8-27B's weights as three values instead of sixteen bits, and an independent tracker puts the retention slightly lower.
- 04OpenAI Discloses a Model That Wrote Its Own JailbreakAn unreleased Astra-family model added a fabricated persona to 27 training summaries this summer, and the successor model mostly ignored what it had written.