Anthropic alleges Moonshot routed nearly 300,000 Kimi user requests through Claude via 5,380 fraudulent accounts, mainly appearing to originate in Singapore and Japan, in a suspected effort to improve Kimi through mod... Anthropic says the activity focused on Claude Opus and moved to newly released public models wit...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Anthropic’s latest report allege about Moonshot AI’s covert use of Claude—including the nearly 300,000 user requests allegedly rout. Article summary: Anthropic’s September 2026 threat report alleges that Moonshot covertly sent Kimi-user requests to Claude and used the resulting outputs in a systematic attempt to replicate Claude’s capabilities. These are allegations b. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts w
Anthropic’s September 2026 threat-intelligence report alleges that Moonshot AI covertly sent requests submitted to its Kimi service to Claude, returned the answers as Kimi outputs, and collected those outputs as part of a broader effort to extract frontier-model capabilities. The company describes this as illicit distillation—not routine use of a third-party AI service. The allegations have not been publicly adjudicated. 15
Anthropic says it identified one Moonshot-linked operation involving nearly 300,000 customer requests sent primarily to Claude Opus. It attributed the traffic to 5,380 fraudulent accounts, which it says largely appeared to be located in Singapore and Japan. In Anthropic’s account, Kimi users were not told their requests were being processed by Claude rather than Moonshot’s own model. 15
The company says the operators disproportionately targeted Claude Opus and began querying newly released, generally available Claude models within 24 hours of release. Anthropic interprets that timing as evidence that the aim was to capture new capabilities quickly. 15
Distillation is a legitimate machine-learning technique in some settings: a developer can train a smaller model from the outputs of a model it controls or has permission to use. Anthropic’s allegation is that this case was different because the activity allegedly used fraudulent accounts, proxies, and access that violated its terms and regional restrictions. 13
15
Anthropic says a competing model can be improved by gathering a large, varied set of responses from a more capable model, particularly on tasks such as reasoning, coding, and tool use. Its suspicion is that Claude-generated outputs were being used to improve Kimi. That is an attribution and assessment by Anthropic, rather than an independently established finding. 15
The September report is a more detailed case within a pattern Anthropic had disclosed in February 2026. In that earlier disclosure, Anthropic alleged that DeepSeek, Moonshot, and MiniMax generated more than 16 million Claude exchanges through about 24,000 fraudulent accounts in order to improve their own models. 13
The roughly 300,000-request Moonshot figure should therefore not be treated as a replacement for the 16 million total. It describes a specific alleged routing operation, while the February figure covered activity attributed collectively to three labs. 13
15
Anthropic’s September report says it also identified and disrupted additional distillation attacks against Claude from seven China-based labs after the February disclosure. It says those efforts targeted generally available models, not models unavailable to the public. 15
Separate from Anthropic’s own reporting, U.S. agencies said in a September advisory that six China-based AI companies—DeepSeek, Moonshot, Alibaba, MiniMax, StepFun, and Z.AI—had extracted billions of tokens from U.S. frontier models through millions of requests. The advisory characterized the alleged activity as industrial-scale distillation and said it involved models from Anthropic, OpenAI, Google, and xAI. 33
That government allegation is broader than the Moonshot case and broader than Claude alone. It also remains an allegation rather than a public legal or technical adjudication. 33
Anthropic says it disrupted the identified activity, banned associated accounts, and built detections around the operation’s behavioral signatures in anticipation that new accounts could be created. 15
Its recommended approach is layered rather than dependent on one account ban:
The central point of Anthropic’s report is not that all model distillation is improper. It is that, in the company’s view, high-volume extraction using allegedly fraudulent identities and undisclosed routing can let a competitor reproduce valuable capabilities while bypassing the provider’s access rules and safeguards. 13
15
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Anthropic alleges Moonshot routed nearly 300,000 Kimi user requests through Claude via 5,380 fraudulent accounts, mainly appearing to originate in Singapore and Japan, in a suspected effort to improve Kimi through mod...
Anthropic alleges Moonshot routed nearly 300,000 Kimi user requests through Claude via 5,380 fraudulent accounts, mainly appearing to originate in Singapore and Japan, in a suspected effort to improve Kimi through mod... Anthropic says the activity focused on Claude Opus and moved to newly released public models within 24 hours; it says it disrupted the accounts and strengthened behavioral detection.
The case builds on Anthropic’s February claim that DeepSeek, Moonshot, and MiniMax collectively made more than 16 million Claude exchanges through roughly 24,000 fraudulent accounts.