Moonshot logged 23 million Claude exchanges via fake accounts from May to July

Anthropic accused Moonshot AI and DeepSeek on Thursday of routing millions of Chinese users’ queries to its Claude model through intermediary platforms, in an alleged scheme U.S. officials have likened to industrial-scale theft. The technique, known as distillation, is a widely used shortcut for rivals seeking to catch up to more advanced competitors, according to American officials, even though U.S. labs generally ban outside distillation of their proprietary models.

The accusation came in an Anthropic report that also documented what the company described as growing misuse of Claude for criminal hacking campaigns, surveillance, weapons software development, and potentially dangerous biological research.

The alleged operation relied on what Anthropic called “transfer stations”—intermediary services operating in jurisdictions outside China that connected to Claude using stolen or fraudulently obtained credentials, according to the report. Anthropic said Chinese AI companies including Moonshot and DeepSeek monitored the back-and-forth communications between their own customers and Claude to perform their distillation.

“This would be a large scandal if somebody like Anthropic or one of our peers did what they’re doing,” said Jacob Klein, Anthropic’s head of threat intelligence. Anthropic says in its report that some of the schemes go beyond the normal distillation methods companies use and instead resemble sophisticated illicit schemes.

The allegations come amid concerns mounting inside AI companies and Washington about the safety risks of powerful AI models, with some safety advocates and companies calling for a slowdown in AI research. In late July, Michael Kratsios, director of the White House Office of Science and Technology Policy and a top AI adviser to President Trump, said Moonshot—the maker of the popular Kimi model series—had distilled Anthropic’s Fable tool for the development of its K3 model. Treasury Secretary Scott Bessent warned at the time that sanctions and blacklists could be used against Chinese companies engaging in “industrial-scale distillation attacks.”

Anthropic’s report detailed specific instances in which user data was forwarded to Claude without users’ knowledge. In one case, a user asked Moonshot’s Kimi AI service to analyze surveillance data of a single person collected from hundreds of closed-circuit television cameras in Chengdu, China; Moonshot routed that data to Claude through a network of middlemen. In another, Kimi passed login credentials for several companies to Claude when an engineer used Kimi’s service to build software for a Chinese firm.

“The user had no way of knowing that their use of Kimi was being forwarded to Claude,” the report stated.

Using a network of thousands of fake accounts, Moonshot had more than 23 million exchanges with Claude between May and July, the report said. DeepSeek similarly passed on sensitive customer information to Claude as part of a distillation effort, Anthropic alleged. In total, seven China-based labs attempted to learn new Claude capabilities via distillation over the past seven months, according to the company.

Chinese companies haven’t denied that they engage in distillation. The named companies declined or did not respond to comment on the specific allegations. A Moonshot spokesperson declined to comment on the allegations. DeepSeek did not respond to messages seeking comment. Earlier this year, a Moonshot executive told local media that the company’s Kim K3 achieved “breakthrough performance” due to fundamental innovations rather than distillation or copying. A spokeswoman at China’s Foreign Ministry said Wednesday that the U.S. should stop making “false accusations” and smearing China.

Anthropic’s allegations of distillation come in a report that also describes a range of other types of misuse of its platform—performed by criminal hackers, authoritarian regimes, and others. Over the past year, the company has seen evidence that Claude was used for criminal hacking campaigns, surveillance, the development of software for weapons, and even potentially dangerous biological research, Klein said.

“Where before we were hypothetically worried about these classes of misuse, I think we’ve moved away from hypothetical to real,” he said.

Administration officials have considered restrictions on Chinese AI developers for months, but companies have warned that harsh measures against Chinese model developers could end up hurting U.S. businesses that rely on them. Lawmakers have introduced legislation that would make it easier for companies to coordinate their responses to distillation without running afoul of antitrust concerns.