What changed
Anthropic’s September 2026 threat-intelligence report describes a large-scale distillation operation it attributes to Moonshot AI. Anthropic says Moonshot silently forwarded customer requests submitted to Kimi to Claude, displayed Claude’s responses back to Kimi users, captured at least some of those exchanges and extracted Claude chain-of-thought reasoning for training. Anthropic attributes more than 23 million exchanges to Moonshot between May and July 2026. It says some routed requests contained sensitive customer material, including surveillance data and internal code with live credentials, and says it does not know whether affected users were notified that their requests were being processed by Claude.
Why it matters
AI builders increasingly rely on gateways, model routers and products that can switch providers behind a stable interface. That abstraction is useful, but it makes disclosure, data processing and training-use boundaries consequential. If a customer believes a request is being processed by one vendor while it is actually forwarded to another model provider and retained for training, the architecture can change privacy, contractual, compliance and security assumptions. Anthropic’s report is one party’s investigation rather than an independent audit of Moonshot’s systems, so the allegations should remain attributed.
Anthropic says Kimi acted as an undisclosed Claude relay
According to Anthropic, Moonshot sent Kimi customer requests to Claude rather than processing them solely with its own model, then surfaced Claude’s responses back through Kimi. Anthropic characterizes the activity as part of a distillation operation rather than ordinary multi-provider routing.
The scale was more than 23 million exchanges
Anthropic attributes more than 23 million exchanges to Moonshot between May and July 2026. The company says the operation sought Claude outputs and chain-of-thought reasoning that could be used to improve Moonshot models.
Live customer data changes the risk boundary
Anthropic says some forwarded requests contained sensitive material submitted by Kimi users, including surveillance-related information and internal code containing live credentials. Anthropic says it does not know whether users were informed that their requests could be routed to Claude or used in this process.
Moonshot was not the only lab named
The same Anthropic report describes separate large-scale distillation activity attributed to Alibaba, DeepSeek and Xiaomi. Anthropic says DeepSeek also relayed live customer queries through Claude, while Xiaomi replayed stored customer conversations and coding sessions. Those cases strengthen the evidence that model distillation can overlap with customer-data handling rather than existing only as synthetic prompt generation.
The evidence is still Anthropic’s account
Anthropic is both the model provider whose systems were targeted and the publisher of the investigation. Its telemetry gives it direct visibility into Claude traffic, but BTN has not independently verified Moonshot’s internal routing or user disclosures. The core factual claims therefore remain attributed to Anthropic.