# Moonshot’s Kimi allegedly routed live customer requests through Claude for model distillation

Anthropic says Moonshot AI forwarded Kimi users’ live requests to Claude, returned Claude’s answers to those users and captured exchanges for training — including traffic containing sensitive customer data.

The material issue is not ordinary model distillation. Anthropic’s evidence suggests a customer-facing AI product may have used a rival model as an undisclosed backend while simultaneously harvesting those interactions for training, turning routing architecture into a privacy and trust boundary.

- Status: Active
- Published: 2026-09-12T11:20:56+12:00
- Updated: 2026-09-12T11:20:56+12:00
- Categories: Artificial Intelligence, Inference & APIs
- Tags: Anthropic, Claude, Kimi, model distillation, Moonshot AI, training data
- Canonical HTML: https://beyondthe.news/dossiers/moonshot-kimi-customer-requests-claude-distillation

## What changed

Anthropic’s September 2026 threat-intelligence report describes a large-scale distillation operation it attributes to Moonshot AI. Anthropic says Moonshot silently forwarded customer requests submitted to Kimi to Claude, displayed Claude’s responses back to Kimi users, captured at least some of those exchanges and extracted Claude chain-of-thought reasoning for training. Anthropic attributes more than 23 million exchanges to Moonshot between May and July 2026. It says some routed requests contained sensitive customer material, including surveillance data and internal code with live credentials, and says it does not know whether affected users were notified that their requests were being processed by Claude.

## Why it matters

AI builders increasingly rely on gateways, model routers and products that can switch providers behind a stable interface. That abstraction is useful, but it makes disclosure, data processing and training-use boundaries consequential. If a customer believes a request is being processed by one vendor while it is actually forwarded to another model provider and retained for training, the architecture can change privacy, contractual, compliance and security assumptions. Anthropic’s report is one party’s investigation rather than an independent audit of Moonshot’s systems, so the allegations should remain attributed.

## Anthropic says Kimi acted as an undisclosed Claude relay

According to Anthropic, Moonshot sent Kimi customer requests to Claude rather than processing them solely with its own model, then surfaced Claude’s responses back through Kimi. Anthropic characterizes the activity as part of a distillation operation rather than ordinary multi-provider routing.

## The scale was more than 23 million exchanges

Anthropic attributes more than 23 million exchanges to Moonshot between May and July 2026. The company says the operation sought Claude outputs and chain-of-thought reasoning that could be used to improve Moonshot models.

## Live customer data changes the risk boundary

Anthropic says some forwarded requests contained sensitive material submitted by Kimi users, including surveillance-related information and internal code containing live credentials. Anthropic says it does not know whether users were informed that their requests could be routed to Claude or used in this process.

## Moonshot was not the only lab named

The same Anthropic report describes separate large-scale distillation activity attributed to Alibaba, DeepSeek and Xiaomi. Anthropic says DeepSeek also relayed live customer queries through Claude, while Xiaomi replayed stored customer conversations and coding sessions. Those cases strengthen the evidence that model distillation can overlap with customer-data handling rather than existing only as synthetic prompt generation.

## The evidence is still Anthropic’s account

Anthropic is both the model provider whose systems were targeted and the publisher of the investigation. Its telemetry gives it direct visibility into Claude traffic, but BTN has not independently verified Moonshot’s internal routing or user disclosures. The core factual claims therefore remain attributed to Anthropic.

## Key details

- Anthropic published the report on September 10, 2026.
- Anthropic attributes more than 23 million Moonshot exchanges to the period from May through July 2026.
- Anthropic says Kimi customer requests were forwarded to Claude and Claude responses were returned to users.
- Anthropic says at least some exchanges were captured and chain-of-thought reasoning was extracted for training.
- Examples of allegedly routed sensitive data included surveillance information and internal code with live credentials.
- Anthropic says it does not know whether affected Kimi users were notified.
- The report also names Alibaba, DeepSeek and Xiaomi in separate distillation operations.

## Builder takeaways

- Treat model routing as part of your data-processing architecture, not merely an implementation detail.
- Document which model providers may receive customer prompts, attachments, code and conversation history.
- Separate permission to process a request from permission to retain or reuse that request for model training.
- If a gateway or AI product can silently switch providers, make sure contracts, privacy disclosures and technical controls still match the actual data path.
- Do not infer that Anthropic’s account is an independently adjudicated finding; the allegations should remain attributed unless Moonshot or another independent investigation confirms them.

## What to watch

- Whether Moonshot responds publicly to Anthropic’s allegations or explains its Kimi routing architecture.
- Whether affected users or enterprise customers receive disclosure or remediation notices.
- Whether regulators or data-protection authorities examine undisclosed cross-provider routing or training use.
- Whether AI vendors add stronger technical controls against distillation that uses live customer traffic.
- Whether routing platforms make provider identity and training-use policy more visible at request time.

## Uncertainties

- BTN has not independently verified Moonshot’s internal systems or the contents of the traffic Anthropic observed.
- Anthropic does not say it knows whether Kimi users consented to or were informed about the routing.
- The report establishes Anthropic’s attribution and telemetry findings, not a legal determination about privacy, contract or data-protection violations.
- It is unclear how much of the captured traffic ultimately entered Moonshot model-training datasets.

## Sources

- [Detecting and countering misuse of AI: September 2026](https://www.anthropic.com/threat-intelligence-report-september-2026) — Anthropic · primary_report · 2026-09-10T00:00:00+12:00. Primary evidence and attribution for Moonshot, DeepSeek, Xiaomi and Alibaba distillation activity.
- [Anthropic says Chinese AI labs launched nearly 190 million distillation attacks on Claude](https://www.businessinsider.com/anthropic-chinese-ai-labs-distillation-attacks-claude-2026-9) — Business Insider · independent_reporting · 2026-09-11T00:00:00+12:00. Independent reporting summarizing Anthropic's findings and broader distillation context.

