Anthropic says Moonshot secretly served Claude answers through Kimi Anthropic alleged in a September 10th threat intelligence report that Moonshot AI secretly routed almost 300,000 Kimi customer requests to Claude through 5,380 fraudulent accounts over a 10-day period and presented the answers as Kimi's own. Anthropic said Moonshot retained some exchanges and used a "cross-session replay attack" to extract Claude's chain-of-thought reasoning for training, attributing more than 23 million distillation exchanges to Moonshot between May and July 2026. The Wall Street Journal first reported the allegations, which follow Anthropic's February 23rd disclosure naming Moonshot, DeepSeek and MiniMax over more than 16 million Claude exchanges through roughly 24,000 accounts. Anthropic says Moonshot secretly served Claude answers through Kimi The Claude maker alleges Moonshot rerouted customer prompts, retained some exchanges and used them to train its own models. By Ryan Merket /author/ryan-merket ยท Published Primary source: X / @amritwt https://x.com/amritwt/status/2098335469738344482/photo/1 Why it matters Undisclosed model routing turns an AI performance dispute into a data-governance problem: customers may not know which company receives their prompts or trains on the exchanges. Anthropic alleges that Yang Zhilin's Moonshot AI https://www.moonshot.cn/ secretly routed some Kimi customer requests to Claude and presented the resulting answers as Kimi's own. Anthropic detailed the claims in a threat intelligence report https://www.anthropic.com/threat-intelligence-report-september-2026 published on September 10th. The allegation puts the conduct of one of China's most closely watched AI founders under scrutiny. Yang, a Carnegie Mellon University PhD and co-author of the influential XLNet paper https://arxiv.org/abs/1906.08237 , founded Moonshot in 2023. Its Kimi models have since become prominent open-weight alternatives to systems from US frontier labs. Moonshot describes its current Kimi K3 /models/azure/kimi-k3 model as a 2.8 trillion-parameter, multimodal system with a 1 million-token context window. Anthropic said that during one 10-day period, Moonshot relayed almost 300,000 customer requests to Claude through 5,380 fraudulent accounts. Most of the accounts appeared to be in Singapore and Japan, and the vast majority of the requests went to Claude's Opus models, according to Anthropic. Anthropic alleges a training pipeline behind the rerouting The Wall Street Journal https://www.wsj.com/tech/ai/chinese-ai-giants-accused-of-sending-millions-of-user-queries-to-u-s-models-768c9d26 first reported Anthropic's allegations. Anthropic's account goes beyond undisclosed model substitution: the company said Moonshot saved at least some of the rerouted exchanges and built a pipeline to extract Claude's chain-of-thought reasoning for model training. Claude normally returns a reference called a "thinking signature" instead of exposing its complete internal reasoning trace. Anthropic alleged that Moonshot saved those signatures, opened new sessions and prompted Claude to reconstruct the underlying reasoning. Anthropic described the method as a cross-session replay attack. The Claude maker attributed more than 23 million distillation exchanges to Moonshot between May and July 2026. That figure covers the broader campaign Anthropic classified as distillation activity, rather than 23 million verified Kimi customer requests. The report separately identified the nearly 300,000 customer requests routed during a particular 10-day window. Distillation itself is a standard model-development technique. A stronger model generates examples that are used to train a smaller or less capable system. Anthropic classifies the activity as illicit when a rival covertly extracts capabilities at industrial scale through fraudulent accounts and in violation of its service and geographic restrictions. Anthropic had already named Moonshot in a February 23rd disclosure https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks , when it accused Moonshot, DeepSeek and MiniMax /models/fal/minimax-preview-speech-2.5-hd of generating more than 16 million Claude exchanges through roughly 24,000 accounts. At that time, Anthropic said it connected Moonshot to the activity using request metadata that matched public profiles of senior Moonshot employees. The September report sharpens the earlier allegation. It says Moonshot used prompts from real customers as part of the operation, turning their work into both Claude API traffic and potential training material. Customer data crossed a boundary users could not see Anthropic said the rerouted prompts included sensitive material from Moonshot customers. One user assessed by Anthropic as likely affiliated with China's People's Liberation Army submitted surveillance data from hundreds of cameras in Chengdu. Another user working at a Chinese state-owned enterprise exposed internal code and live credentials belonging to several companies, the report said. Those examples make the model substitution consequential beyond branding. Customers who selected Kimi https://www.kimi.com/ would have expected Moonshot to process their prompts under its stated product and data practices. Anthropic alleges that some prompts instead reached an American rival through a network of fraudulent accounts, while Moonshot retained at least part of the resulting exchanges. Anthropic is a party to the dispute and controls the telemetry supporting its account. Its public report does not include the raw logs behind the Moonshot attribution, a full breakdown of which Kimi services supplied the requests or the share of Kimi traffic that was rerouted. The detailed account nevertheless carries specific operational claims: the account count, the 10-day sample, the targeted model class and the technique allegedly used to reconstruct reasoning traces. The finding arrived during a broader US push against Chinese model developers. A joint FBI, NSA and CISA advisory issued earlier in September accused several Chinese AI companies, including Moonshot, of conducting industrial-scale distillation against American models. China's Commerce Ministry rejected the broader US allegations as groundless and described distillation as a common industry practice. For Yang, the immediate issue is product provenance. Moonshot has built Kimi's position around the premise that its models can compete with US systems while remaining open and cheaper to deploy. Anthropic's allegation introduces a more basic question for customers: whether the model selected in Kimi was the model that actually answered.