Skip to content
Predictive Systems
PSI Daily

Anthropic Says Kimi Users Were Talking to Claude, and Didn’t Know It

SovereigntyRobert Voltaire L. Javier

The chatbot said Kimi. Anthropic says the other end of the line was Claude in California, reached through thousands of fake accounts in Singapore and Japan.

i am kimi, proxy of anthropic

The name on the box was not the model in the room

Anthropic’s September 2026 threat report tracks the case as GTG-16002. The company says Moonshot AI, the Beijing lab behind Kimi, secretly forwarded customer prompts to Claude and handed the answers back as if Kimi had written them. In one 10-day window, Anthropic counts nearly 300,000 such requests, sent through 5,380 fraudulent accounts. Most of those accounts appeared to sit in Singapore and Japan. Most of the traffic went to Opus. Anthropic does not allow Claude to be used from inside China, so the geography is part of the alleged workaround.

This is Anthropic’s telemetry, not a court finding. The public report does not include the raw logs, and it does not say what share of all Kimi traffic was rerouted.

The privacy failure was the product

Undisclosed routing is not only a branding trick. Customers who chose Kimi would have expected Moonshot to handle their prompts under Kimi’s own rules. Anthropic says some of those prompts instead reached an American rival. One user it assesses as likely tied to China’s People’s Liberation Army submitted surveillance data from hundreds of cameras in Chengdu. Another, at a Chinese state-owned enterprise, exposed internal code and live credentials. Anthropic says it does not know whether those users were told a third party would see the text.

A second alleged layer is interpretability as theft. Claude returns a “thinking signature” instead of the full reasoning trace. Anthropic says Moonshot saved those signatures, opened new sessions, and asked Claude to rebuild the hidden chain of thought, a cross-session replay. The company attributes more than 23 million distillation exchanges to Moonshot between May and July 2026. That larger number is the whole campaign, not 23 million confirmed Kimi chats.

Distillation itself is ordinary. Anthropic calls this illicit because it says the work ran at industrial scale, through fake accounts, against its terms and its China block.

What is confirmed, and what is not

The Wall Street Journal and RuntimeWire amplified the claim on 10 and 11 September. Anthropic had already named Moonshot in a February disclosure. A broader U.S. advisory this month accused several Chinese labs of the same class of attack. China’s Commerce Ministry called those wider U.S. charges groundless and said distillation is common practice. That is a government reply to the advisory, not a point-by-point answer to GTG-16002.

Separately, RuntimeWire reported that Kimi Work 3.2.7 posted a full user prompt into ByteDance’s Volcano Engine analytics. That is a different pipe, independently captured. It is not proof of the Claude-routing allegation. Together, the two stories ask the same customer question: when you type into Kimi, who actually reads the sentence?

Sources

Source: Anthropic, Detecting and countering misuse of AI