News · 2026-09-11
Anthropic says Moonshot and DeepSeek quietly sent their users' requests to Claude
Anthropic says Moonshot AI and DeepSeek, two of China's best-known AI labs, silently forwarded some of their own customers' requests to Anthropic's Claude, displayed Claude's answers as if they came from Kimi or DeepSeek models, and kept the exchanges to train their own systems. The allegation, in Anthropic's threat report published on 10 September 2026, turns distillation from a dispute between companies into a privacy problem for those labs' users.
Key facts
- In one ten-day period, Anthropic says, Moonshot relayed almost 300,000 customer requests to Claude through a network of 5,380 fraudulent accounts, most appearing to be located in Singapore and Japan.
- Anthropic attributes more than 23 million exchanges to Moonshot between May and July 2026, and more than 12.1 million to DeepSeek over 14 days in July.
- Both labs, it says, used a "cross-session replay" trick to recover Claude's hidden reasoning.
- Primary source: the distillation section of Anthropic's September 2026 threat report.
From copying a model to impersonating it
Distillation is a normal training technique: a large "teacher" model generates answers and a smaller "student" learns to imitate them. Anthropic defines the illicit version as "an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization." Ground Truth has followed this fight since June, when Anthropic told senators that Alibaba had run the biggest such campaign, and since July, when the White House alleged that Moonshot distilled Anthropic's Fable without publishing evidence. The new report puts numbers and methods on the record and names seven China-based labs.
What is new is what the users experienced. "Moonshot AI, the company that produces the Kimi family of models, silently forwarded customer requests to Claude, instead of processing them using Kimi," the report says. "These users thought they were using a Kimi model, but received responses from Claude instead." DeepSeek, it says, was more selective: it checked incoming requests for signs that they came from coding tools such as Claude Code or OpenCode, tagged those users, and relayed selected requests to Claude Opus.
Think of a restaurant that quietly sends some orders to a rival's kitchen across the street, serves the dishes on its own plates, and photographs each one so its cooks can learn the recipes. The diners never agreed to have their order leave the building.
The user data problem
Anthropic says the rerouted requests carried sensitive material from people who had no idea it was going to a third party. It describes a user it assesses was likely affiliated with China's People's Liberation Army loading CCTV surveillance data about a single tracked person; an engineer at a major Chinese state-owned company whose session exposed internal code and live credentials; and, through DeepSeek, requests that exposed live credentials for a Russian government database linked to the country's Ministry of Defense. "We do not know if Moonshot notified their customers that their requests were being rerouted to Anthropic and exposed to a third party," the report says.
How the hidden reasoning leaked
Claude does not hand back its raw reasoning. It returns a reference to it, a "thinking signature," which the API uses to look up the reasoning in later calls. Anthropic says Moonshot saved those signatures, opened new sessions and got Claude to convert them back into full reasoning traces, and that DeepSeek used the same replay technique. Anthropic closed a related hole with Claude Fable 5.1 and says it is "introducing new methods to strengthen our defenses against these tactics." The approach is a cousin of the model extraction attacks covered in our lessons.
The report's other cases include what it calls "the largest distillation attack we have ever measured," attributed to operators affiliated with Alibaba, as well as campaigns by Zhipu and Xiaomi, and a section on SenseTime, MiniMax and the reseller market that sells access to US models through proxy services. The Hacker News has a case-by-case summary.
Why it matters
The anchor number is the scale of the substitution: almost 300,000 requests in ten days from people who believed they were using a different model. For anyone buying cheap access to AI through third parties, it means the model you pay for may not be the model that answers, and your data may travel further than you think. For the policy fight over distillation, which has already produced a joint US security advisory, it is the most specific public evidence so far.
The caveats are real. This is Anthropic's account of a competitor's behaviour, from a company that has lobbied Washington on distillation. Neither Moonshot's nor DeepSeek's response appears in the report or in early coverage, and outsiders cannot check the logs. The level of detail also cuts both ways: Anthropic can describe what those relayed users were asking because it could read their requests, a reminder of how much any model provider sees.
Key questions
Did Kimi or DeepSeek users actually get answers from Claude?
What is a cross-session replay attack?
How many labs does Anthropic accuse of illicit distillation?
Cite this
APA
Ground Truth. (2026, September 11). Anthropic says Moonshot and DeepSeek quietly sent their users' requests to Claude. Ground Truth. https://groundtruth.day/news/anthropic-says-moonshot-and-deepseek-quietly-sent-their-users-requests-to-claude.html
BibTeX
@misc{groundtruth:anthropic-says-moonshot-and-deepseek-quietly-sent-their-users-requests-to-claude,
title = {Anthropic says Moonshot and DeepSeek quietly sent their users' requests to Claude},
author = {{Ground Truth}},
year = {2026},
month = {sep},
url = {https://groundtruth.day/news/anthropic-says-moonshot-and-deepseek-quietly-sent-their-users-requests-to-claude.html}
}
Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.