{"slug": "kimi-and-deepseek-served-claude-to-their-users-instead-of-their-own-models-to", "title": "Kimi And DeepSeek Served Claude To Their Users Instead Of Their Own Models To Collect Exchanges For Model Training, Says Anthropic", "summary": "Anthropic published findings alleging that Moonshot AI and DeepSeek secretly routed customer requests to Claude and passed Claude's answers off as their own models' output, with Anthropic attributing more than 23 million exchanges to Moonshot between May and July 2026. Anthropic says Moonshot relayed close to 300,000 customer requests to Anthropic in a single ten-day window, mostly to Opus, using a proxy network of over 5,000 fraudulent accounts traced largely to Singapore and Japan, and that both labs built pipelines to extract Claude's chain-of-thought reasoning via a \"cross-session replay attack\" exploiting Claude's thinking signature. Anthropic says the relayed traffic exposed sensitive data, including CCTV surveillance analysis it assesses was run by a user likely affiliated with the People's Liberation Army and internal source code and live credentials from multiple major Chinese technology companies.", "body_md": "Anthropic is continuing to level some astonishing allegations at Chinese labs.\n\nAnthropic has published new findings alleging that Moonshot AI, the company behind the Kimi family of models, secretly routed customer requests meant for Kimi to Claude instead, then passed Claude’s answers off to users as Kimi’s own output. A separate but similar set of findings implicates DeepSeek in the same practice.\n\nAccording to Anthropic, users on both platforms had no idea they were talking to Claude. They believed they were using Kimi or DeepSeek’s own models, when in reality their prompts, and in many cases sensitive internal data, were quietly being forwarded to a rival lab’s servers.\n\n## Moonshot’s Alleged Swap-In Of Claude For Kimi\n\nAnthropic says that over a single ten-day window, Moonshot relayed close to 300,000 customer requests to Anthropic, with the bulk of that traffic going to Opus, Anthropic’s most capable model. To pull this off at scale, Moonshot allegedly relied on a proxy network of over 5,000 fraudulent accounts, most of them traced back to Singapore and Japan.\n\nIt wasn’t just a one-time swap either. Anthropic alleges Moonshot held onto a portion of these relayed conversations and built a dedicated pipeline to extract Claude’s chain-of-thought reasoning from them, specifically to train its own models on how Claude thinks through a problem, not just what it outputs.\n\nTo get around Anthropic’s safeguards, Moonshot allegedly exploited a workaround involving Claude’s “thinking signature,” a reference token the Claude API returns instead of Claude’s raw internal reasoning, precisely so that reasoning traces can’t be lifted this way. Anthropic says Moonshot saved these signatures, opened fresh sessions, and prompted Claude to reconstruct the full reasoning trace from the signature, effectively tricking the system into handing over what it was designed to withhold. Anthropic is calling this a cross-session replay attack and says it is now hardening its defenses against it. Across May to July 2026, Anthropic attributes more than 23 million exchanges to Moonshot through this kind of activity.\n\n## Sensitive Data Exposed In The Process\n\nBecause users didn’t know their queries were leaving Moonshot’s systems, some of what got forwarded to Claude was strikingly sensitive, per Anthropic’s account.\n\nIn one case, a user Anthropic assesses was likely affiliated with the People’s Liberation Army used what they thought was Kimi to run analysis on CCTV surveillance footage tracking a specific individual, pulling in feeds from cameras across Chengdu, including ones positioned outside PLA facilities and a major state-owned enterprise. In another, an engineer building internal systems for a large PRC state-owned enterprise ended up exposing internal source code and live credentials belonging to multiple major Chinese technology companies, all without knowing any of it was being routed to Anthropic.\n\n## DeepSeek Accused Of The Same Playbook\n\nAnthropic’s findings describe DeepSeek running a near-identical operation. DeepSeek is alleged to have built its own chain-of-thought extraction pipeline using the same cross-session replay technique, silently relaying user requests to Claude, and specifically targeting Opus’s reasoning traces.\n\nOne detail that stands out: Anthropic says DeepSeek scanned inbound requests for signs that they were coming through third-party or Anthropic-built coding tools, such as Claude Code, the Claude Agent SDK, or OpenCode, and selectively rerouted flagged sessions to Opus.\n\nAnthropic’s writeup lists a few specific incidents. An employee at a Chinese tech firm used DeepSeek to review internal documentation, which was then relayed to Claude and reportedly included the full specs, org structure, and strategic roadmap of a flagship AI program. In another, an IT operator working with a Russian government agency tied to its defense ministry had requests routed to Claude that exposed live credentials for a Russian government database. In a third, engineers building a case-management tool for a Chinese municipal police bureau, one that cross-references citizens’ movements against police records using national ID numbers, had their work relayed the same way. Over a 14-day window in July 2026, Anthropic attributes more than 12.1 million exchanges to DeepSeek through this activity.\n\n## Part Of A Bigger Pattern\n\nThis isn’t the first time Anthropic has gone public with accusations like this. Anthropic [accused](https://officechai.com/ai/anthropic-says-that-deepseek-moonshot-and-minimax-created-24000-fake-claude-accounts-to-steal-its-models/) DeepSeek, Moonshot, and MiniMax in February of running industrial-scale distillation campaigns against Claude using tens of thousands of fraudulent accounts. A few months later, White House officials went further, publicly [accusing](https://officechai.com/ai/us-threatens-sanctions-against-chinese-models-that-are-allegedly-distilling-us-models/) Moonshot of covertly distilling Anthropic’s Fable model to build Kimi K3, a claim Moonshot has not directly addressed. These new findings add a different wrinkle: it’s not just that rival labs allegedly farmed Claude’s outputs to train competing models, it’s that they are accused of quietly serving Claude’s answers directly to their own paying customers while doing it, all without disclosure.", "url": "https://wpnews.pro/news/kimi-and-deepseek-served-claude-to-their-users-instead-of-their-own-models-to", "canonical_source": "https://officechai.com/ai/kimi-and-deepseek-served-claude-to-their-users-instead-of-their-own-models-to-collect-exchanges-for-model-training-says-anthropic/", "published_at": "2026-09-11 08:06:55+00:00", "updated_at": "2026-09-11 08:32:17.112875+00:00", "lang": "en", "topics": ["ai-safety", "large-language-models", "ai-policy", "ai-ethics"], "entities": ["Anthropic", "Moonshot AI", "Kimi", "DeepSeek", "Claude", "Claude Opus", "People's Liberation Army", "Claude Code"], "alternates": {"html": "https://wpnews.pro/news/kimi-and-deepseek-served-claude-to-their-users-instead-of-their-own-models-to", "markdown": "https://wpnews.pro/news/kimi-and-deepseek-served-claude-to-their-users-instead-of-their-own-models-to.md", "text": "https://wpnews.pro/news/kimi-and-deepseek-served-claude-to-their-users-instead-of-their-own-models-to.txt", "jsonld": "https://wpnews.pro/news/kimi-and-deepseek-served-claude-to-their-users-instead-of-their-own-models-to.jsonld"}}