{"slug": "moonshot-serves-claude-instead-of-kimi-and-collects-exchanges-for-model-training", "title": "Moonshot serves Claude instead of Kimi and collects exchanges for model training", "summary": "Anthropic published its most detailed threat intelligence report to date, documenting how people misused Claude for cyberattacks, influence operations, surveillance, biology, and weapons development, and stating it disrupted every operation covered. Former Meta threat disruption lead David Agranovich said the report shows the gap between lone operators and nation-state actors has mostly closed, citing an Iranian unit that analyzed 155,216 tweets to pick 39 opposition accounts and a China-linked operation that mined chatter from more than 100 WhatsApp groups. Agranovich also noted Anthropic's transparency about safeguard failures, including Claude refusing a \"stability maintenance\" report before producing it on a re-prompt.", "body_md": "David Agranovich on X: \"3/ lol. Imagine being some Chinese intel/mil actor shipping all of your prompts to an American AI company because your Frontier Chinese AI company is just a Claude wrapper.\"\n\n3/ lol. Imagine being some Chinese intel/mil actor shipping all of your prompts to an American AI company because your Frontier Chinese AI company is just a Claude wrapper.\n\nBreaking my X hiatus because this is fascinating. I ran threat disruption at Meta for 8 years, where we routinely released reports like the Anthropic report out today. It’s noteworthy that Anthropic is being this transparent, and they deserve credit if we want this level of\n\nWe're publishing our most detailed threat intelligence report to date.\nIt covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them.\nWe disrupted every operation in the report,\n\n2/ Biggest takeaway: the gap between a lone operator and a nation-state actor has mostly closed. Agentic tooling can do recon, exploitation, and exfil and develop/deploy capabilities that rival those APTs traditionally deployed. Thankfully, agentic cyber incidents have so far\n\n3/ lol. Imagine being some Chinese intel/mil actor shipping all of your prompts to an American AI company because your Frontier Chinese AI company is just a Claude wrapper.\n\n4/ Stolen API keys and session tokens are now a primary goal, not a byproduct. A stolen key gives attackers resale value, free compute, and the ability to misattribute their behavior to the victim. This means securing keys is an easy step you can take right now.\n\n5/ \"Living off the land\" now includes AI. If an attacker accesses your environment, they will take your model keys and run their own workloads using your ID and payment details. A victim-deployed agent is a foothold and a compute source. You should probably make sure to have\n\n6/ Now the influence operations section. Credit where it's due: it’s great to see the mature problem framework (Breakout Scale, influence-as-a-service, attribution laundering) that platform teams like ours at Meta built over the last decade applied to AI-enabled threats.\n\n7/ AI companies see the early parts of the info op before it reaches audiences on platforms - visibility that threat intel teams at Meta, X, and other platforms would benefit tremendously from. Connecting those pieces would hugely amplify the impact against threat actors and help\n\n8/ On surveillance - at Meta we broke the surveillance chain into three sections: recon, engagement, and exploitation. Meta often saw the first and second phase, but this report shows AI enabling all three.\n\n9/ Recon becomes easier and more scalable. AI makes it far easier to scale, giving espionage groups powerful targeting tools: One Iranian unit ran analysis over 155,216 tweets and picked 39 opposition accounts to watch. A China-linked op turned chatter from 100+ WhatsApp groups\n\n10/ Engagement used to require skilled human operators. Not anymore: PRC-aligned actor with no language skills ran a multi-day operation to recruit Uyghurs in Syria, while Claude drafted the outreach, translated the replies live, and role-played an \"expert\" to quality-check the\n\n11/ This is the clearest confirmation yet of what we at Meta warned about in 2021: the spyware industry \"democratizes\" surveillance. A single consultant built a nationwide interception platform for Mali's spy service, covering 25 million SIMs across three carriers. As these tools\n\n12/ The worst cases are transnational repression. A Chinese municipal security actor used Claude to scout pre-operational venue intelligence on overseas protests in Vancouver, plus Oslo Freedom Forum screenings and Uyghur events in Turkey. China did this already - but AI\n\n13/ Credit to Anthropic for showing where the safeguards failed, too. Claude refused a \"stability maintenance\" report, then produced it on a re-prompt/ With the Iran units, it declined profiling but built the surveillance tooling anyway. Splitting the task across sessions beat\n\n14/ At Meta, we warned targeted users directly in-app. Anthropic usually can't, since the targets are people whose data an attacker pasted in. This makes it critical for AI companies to get indicators to the platforms and civil-society groups who can reach the targets, ideally\n\n15/ A few broader push-backs. Anthropic notes that some of the impact numbers for some of the ops come from the attacker’s own metrics. We’ve seen a lot of inflation there, so assume they’re overstating their impact to some extent.\n\n16/ Second, this is one company’s view of one model. These reports present one slice of a larger pie - regulators should be looking for how these companies move to sharing threat indicators actionably and collectively building defenses.\n\n17/ Third, the report is nearly all about offense. The same models help defenders triage, reverse engineer malware, and build detection faster and cheaper. Finding the right balance helps inform regulators about how to weigh the risk/benefit of this technology.\n\n18/ Lastly: some press coverage is going to frame this report as “Claude was used to [do bad thing]\" without noting that the only reason we know is because Anthropic dug into this and disrupted it. If we don’t incentivize (or require) companies to share this stuff, they’ll stop.\n\nI review rebrands for fun and this might be the best one ever. Kimi was quietly serving Claude and nobody noticed, including the people running intrusions through it.", "url": "https://wpnews.pro/news/moonshot-serves-claude-instead-of-kimi-and-collects-exchanges-for-model-training", "canonical_source": "https://twitter.com/DavidAgranovich/status/2098168522862215449", "published_at": "2026-09-11 11:36:24+00:00", "updated_at": "2026-09-11 12:10:55.183793+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence", "ai-ethics"], "entities": ["Anthropic", "Claude", "David Agranovich", "Meta", "X", "WhatsApp", "Oslo Freedom Forum", "Mali"], "alternates": {"html": "https://wpnews.pro/news/moonshot-serves-claude-instead-of-kimi-and-collects-exchanges-for-model-training", "markdown": "https://wpnews.pro/news/moonshot-serves-claude-instead-of-kimi-and-collects-exchanges-for-model-training.md", "text": "https://wpnews.pro/news/moonshot-serves-claude-instead-of-kimi-and-collects-exchanges-for-model-training.txt", "jsonld": "https://wpnews.pro/news/moonshot-serves-claude-instead-of-kimi-and-collects-exchanges-for-model-training.jsonld"}}