cd /news/ai-safety/kimi-and-deepseek-served-claude-to-t… · home topics ai-safety article
[ARTICLE · art-126682] src=officechai.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Kimi And DeepSeek Served Claude To Their Users Instead Of Their Own Models To Collect Exchanges For Model Training, Says Anthropic

Anthropic published findings alleging that Moonshot AI and DeepSeek secretly routed customer requests to Claude and passed Claude's answers off as their own models' output, with Anthropic attributing more than 23 million exchanges to Moonshot between May and July 2026. Anthropic says Moonshot relayed close to 300,000 customer requests to Anthropic in a single ten-day window, mostly to Opus, using a proxy network of over 5,000 fraudulent accounts traced largely to Singapore and Japan, and that both labs built pipelines to extract Claude's chain-of-thought reasoning via a "cross-session replay attack" exploiting Claude's thinking signature. Anthropic says the relayed traffic exposed sensitive data, including CCTV surveillance analysis it assesses was run by a user likely affiliated with the People's Liberation Army and internal source code and live credentials from multiple major Chinese technology companies.

read4 min views6 publishedSep 11, 2026
Kimi And DeepSeek Served Claude To Their Users Instead Of Their Own Models To Collect Exchanges For Model Training, Says Anthropic
Image: Officechai (auto-discovered)

Anthropic is continuing to level some astonishing allegations at Chinese labs.

Anthropic has published new findings alleging that Moonshot AI, the company behind the Kimi family of models, secretly routed customer requests meant for Kimi to Claude instead, then passed Claude’s answers off to users as Kimi’s own output. A separate but similar set of findings implicates DeepSeek in the same practice.

According to Anthropic, users on both platforms had no idea they were talking to Claude. They believed they were using Kimi or DeepSeek’s own models, when in reality their prompts, and in many cases sensitive internal data, were quietly being forwarded to a rival lab’s servers.

Moonshot’s Alleged Swap-In Of Claude For Kimi #

Anthropic says that over a single ten-day window, Moonshot relayed close to 300,000 customer requests to Anthropic, with the bulk of that traffic going to Opus, Anthropic’s most capable model. To pull this off at scale, Moonshot allegedly relied on a proxy network of over 5,000 fraudulent accounts, most of them traced back to Singapore and Japan.

It wasn’t just a one-time swap either. Anthropic alleges Moonshot held onto a portion of these relayed conversations and built a dedicated pipeline to extract Claude’s chain-of-thought reasoning from them, specifically to train its own models on how Claude thinks through a problem, not just what it outputs.

To get around Anthropic’s safeguards, Moonshot allegedly exploited a workaround involving Claude’s “thinking signature,” a reference token the Claude API returns instead of Claude’s raw internal reasoning, precisely so that reasoning traces can’t be lifted this way. Anthropic says Moonshot saved these signatures, opened fresh sessions, and prompted Claude to reconstruct the full reasoning trace from the signature, effectively tricking the system into handing over what it was designed to withhold. Anthropic is calling this a cross-session replay attack and says it is now hardening its defenses against it. Across May to July 2026, Anthropic attributes more than 23 million exchanges to Moonshot through this kind of activity.

Sensitive Data Exposed In The Process #

Because users didn’t know their queries were leaving Moonshot’s systems, some of what got forwarded to Claude was strikingly sensitive, per Anthropic’s account.

In one case, a user Anthropic assesses was likely affiliated with the People’s Liberation Army used what they thought was Kimi to run analysis on CCTV surveillance footage tracking a specific individual, pulling in feeds from cameras across Chengdu, including ones positioned outside PLA facilities and a major state-owned enterprise. In another, an engineer building internal systems for a large PRC state-owned enterprise ended up exposing internal source code and live credentials belonging to multiple major Chinese technology companies, all without knowing any of it was being routed to Anthropic.

DeepSeek Accused Of The Same Playbook #

Anthropic’s findings describe DeepSeek running a near-identical operation. DeepSeek is alleged to have built its own chain-of-thought extraction pipeline using the same cross-session replay technique, silently relaying user requests to Claude, and specifically targeting Opus’s reasoning traces.

One detail that stands out: Anthropic says DeepSeek scanned inbound requests for signs that they were coming through third-party or Anthropic-built coding tools, such as Claude Code, the Claude Agent SDK, or OpenCode, and selectively rerouted flagged sessions to Opus.

Anthropic’s writeup lists a few specific incidents. An employee at a Chinese tech firm used DeepSeek to review internal documentation, which was then relayed to Claude and reportedly included the full specs, org structure, and strategic roadmap of a flagship AI program. In another, an IT operator working with a Russian government agency tied to its defense ministry had requests routed to Claude that exposed live credentials for a Russian government database. In a third, engineers building a case-management tool for a Chinese municipal police bureau, one that cross-references citizens’ movements against police records using national ID numbers, had their work relayed the same way. Over a 14-day window in July 2026, Anthropic attributes more than 12.1 million exchanges to DeepSeek through this activity.

Part Of A Bigger Pattern #

This isn’t the first time Anthropic has gone public with accusations like this. Anthropic accused DeepSeek, Moonshot, and MiniMax in February of running industrial-scale distillation campaigns against Claude using tens of thousands of fraudulent accounts. A few months later, White House officials went further, publicly accusing Moonshot of covertly distilling Anthropic’s Fable model to build Kimi K3, a claim Moonshot has not directly addressed. These new findings add a different wrinkle: it’s not just that rival labs allegedly farmed Claude’s outputs to train competing models, it’s that they are accused of quietly serving Claude’s answers directly to their own paying customers while doing it, all without disclosure.

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/kimi-and-deepseek-se…] indexed:0 read:4min 2026-09-11 ·