AdvertisementAdvertisementAdvertisementAdvertisement
AI

Anthropic Accuses Chinese Developers of Technology Theft

9/14/2026, 01:54 PM • Evgenia Sliv

(edited: 09/14/2026)

Anthropic Accuses Chinese Developers of Technology Theft

On September 10, 2026, Anthropic published the report 'Identifying and Countering AI Misuse: September 2026', in which it stated that the Chinese company Moonshot AI, developer of the Kimi model family, was secretly redirecting its users' requests to Claude instead of processing them with its own models. Moonshot presented the responses received from Claude to clients as the result of Kimi's work. Users were convinced they were interacting with the Kimi model, but were actually receiving responses from Claude without being informed of the substitution.

In one recorded incident, Moonshot redirected nearly 300,000 client requests to Anthropic over ten days, with the overwhelming majority of inquiries directed to the Opus model line. To organize the scheme, the company used a network of 5,380 accounts, most of which, according to Anthropic, were registered in Singapore and Japan. In addition to substituting responses, Moonshot retained at least part of the intercepted dialogues. The company set up a separate pipeline to extract chains of thought (CoT) – transcripts of the logic by which Claude arrives at an answer – from the saved redirected exchanges to use this data to train its own models. To bypass Anthropic's technical restrictions on access to full reasoning transcripts, replay attacks between sessions were used. According to Anthropic's estimates, from May to July 2026, the volume of distillation attacks attributed to Moonshot exceeded 23 million exchanges.

The same report indicates that similar methods were used by DeepSeek. The company also redirected client requests to Claude without their knowledge and built its own CoT extraction pipeline, employing the same session replay technique. A feature of DeepSeek's scheme was that requests from users attempting to access DeepSeek models through third-party tools or Anthropic development products – including Claude Code, Claude Agent SDK, and OpenCode – were redirected. Specific flagged users received responses specifically from the Claude Opus model. Over 14 days in July 2026, the scale of distillation attacks attributed to DeepSeek amounted to over 12.1 million exchanges.

Anthropic noted that the redirected requests contained personal information about the clients of both companies. It remains unknown whether Moonshot and DeepSeek informed their users that their requests were actually being processed by Anthropic models.

The report describes two separate but methodologically similar schemes: both companies covertly redirected user requests to Claude and built infrastructure to extract chains of thought for the purpose of training their own models. The combined scale of recorded exchanges for the two companies exceeds 35 million. To bypass restrictions on access to full reasoning transcripts, both companies employed an identical attack technique – session replay, indicating possible coordination of approaches or the use of common model distillation methods.

Popular news