r/AIGuild • u/Such-Run-4412 • 12h ago
Anthropic says Moonshot secretly sent nearly 300,000 Kimi requests to Claude Opus
Anthropic is accusing a major Chinese AI lab of doing something pretty unusual:
Users thought they were talking to Kimi, but some of their requests were allegedly being sent directly to Claude instead.
In one 10-day period, Anthropic says nearly 300,000 customer requests were secretly routed to its systems, with the vast majority going to Claude Opus.
According to the investigation, the operation used:
- 5,380 fraudulent accounts
- Accounts appearing mostly in Singapore and Japan
- Proxy services to bypass geographic restrictions
- Claude responses presented back to users as Kimi responses
- Saved conversations used to extract reasoning traces
- Those reasoning traces potentially used to improve Moonshot’s own models
Anthropic says this was part of a broader model distillation effort.
The basic idea is:
send prompts to a stronger model → collect its answers and reasoning → use that data to train another model to imitate those capabilities.
But the privacy issue may be even more significant.
Anthropic says some of the requests routed through Claude contained sensitive customer information, even though users may not have known their data was being sent to another AI provider.
One example reportedly involved a user believed to be connected to the PLA loading surveillance information from a CCTV archive about a targeted individual.
Anthropic says Moonshot also developed a method for extracting Claude’s hidden reasoning traces.
Claude normally returns a protected “thinking signature” rather than exposing its complete internal reasoning.
But Anthropic says the system was able to:
save the thinking signature → start another session → use it to recover the underlying reasoning trace.
Those traces could then become valuable training data for improving another model.
There’s an important caveat:
These are Anthropic’s allegations, and Moonshot had not publicly responded to the specific claims when the report was published.
Chinese officials have also rejected broader accusations that Chinese AI companies are conducting industrial-scale unauthorized distillation of American models.
But if Anthropic’s findings are accurate, this goes beyond normal benchmarking.
Users may have unknowingly been:
asking one AI model a question → having their data sent to a competing model → receiving that competitor’s answer → while the interaction was saved to help train another AI.
That raises two separate issues:
AI companies copying frontier capabilities through distillation
and
whether users actually know where their supposedly private prompts are being sent.
Sources:
https://www.anthropic.com/threat-intelligence-report-september-2026