Anthropic accused Chinese companies DeepSeek and Moonshot AI of covertly redirecting user queries to Claude. In some cases, users believed they were interacting with DeepSeek or Kimi, while the requests were actually processed by Claude Opus. The resulting responses and reasoning data could then be used to train their own models.

Kimi may have shown users Claude’s responses

Anthropic claims that Kimi silently forwarded parts of client queries to Claude and displayed the received result as its own response.

Over a single ten-day period, Moonshot sent Anthropic nearly 300,000 user requests, most of which were processed by Claude Opus. Access was gained using a network of 5,380 fake accounts, primarily linked to Singapore and Japan.

Claude Opus

From May to July 2026, Anthropic linked more than 23 million Claude requests to Moonshot.

According to the investigation, Moonshot retained at least part of the conversations and extracted reasoning data from Claude that could be used to train its own models.

DeepSeek sent more than 12 million requests to Claude over two weeks

Over the first 14 days of July 2026, Anthropic recorded more than 12.1 million Claude requests related to DeepSeek.

According to Anthropic, DeepSeek identified users who worked with its models via Claude Code, Claude Agent SDK, and OpenCode, after which individual requests were silently redirected to Claude Opus.

DeepSeek

DeepSeek also allegedly attempted to obtain Claude’s hidden reasoning chains. To do this, the request was repeated in a new session using a special signature that Claude returns instead of its full internal reasoning process. This allowed partial recovery of data that is usually hidden.

Confidential data was exposed in Claude

Along with requests to Anthropic’s infrastructure, information that users initially sent to DeepSeek and Kimi was also included.

Among such cases, Anthropic discovered internal documents from a Chinese technology company, specifications and strategic plans for a large AI project, as well as active credentials for a Russian state database linked to an organization under the Ministry of Defense of Russia.

Through Kimi, surveillance footage from hundreds of cameras in Chengdu, used to analyze the actions of a specific individual, also reached Claude. In another case, an engineer at a major Chinese state-owned enterprise shared internal code and active credentials for several companies with Kimi, unaware that the request was being processed by Claude.

In redirected dialogues, Anthropic also discovered names, email addresses, corporate information, and other sensitive data. The company does not know whether Moonshot and DeepSeek warned users about sending requests to a third-party provider.

Claude’s responses were used to train the models

Anthropic links the situation to distillation, a process where responses from a larger model are used to train another model. While this method is widely used in the industry, the company considers the mass extraction of Claude’s capabilities without permission to be a violation.

Claude Opus 4.5

According to Anthropic, DeepSeek, Moonshot, and Xiaomi sent real user dialogues to Claude and then used the responses as training data. Since February, the company has identified similar campaigns from seven Chinese AI developers.

The largest of these, Anthropic, linked it to Alibaba: between May and July 2026, more than 151 million requests to Claude were recorded. The company believes this data was used in developing the Qwen family of models.

Anthropic blocks accounts associated with such schemes, monitors unusual access methods, and restricts extraction of Claude’s reasoning data. In cases of suspicious activity, the company may also require identity verification.

All accusations against DeepSeek and Moonshot are based on an investigation by Anthropic. Moonshot declined to comment to The Wall Street Journal, while DeepSeek did not respond to the publication’s request.

Follow MobiDevices
Telegram