Illicit model distillation · GTG-16001
Report's allegations about DeepSeek request routing: GTG-16001 case
This page is a Chinese-to-English translation of content from pages 149–150 of Anthropic's September 2026 report. All content involving specific companies is Anthropic's unilateral allegation; this site has not independently verified it, and it does not constitute a finding of illegality.
According to the Anthropic report, DeepSeek also deployed a strategy similar to Moonshot's: building a CoT extraction pipeline, using the same cross-session replay attack to extract Claude's chain-of-thought records, and silently forwarding conversations to Claude without notifying customers. The report also says DeepSeek routed requests from users of third-party coding tools to Claude Opus, including sensitive data from Chinese tech companies, Russian defense agencies, and Chinese public security surveillance systems. All of the above are the publisher's allegations, not this site's independent findings.
What happened
Our investigation shows that DeepSeek also deployed a strategy similar to Moonshot's. DeepSeek built a CoT extraction pipeline that relied on the same cross-session replay attack described above. DeepSeek also silently forwarded conversations to Claude without notifying DeepSeek customers. As with GTG-16002, its customers may not have been told their requests were being routed to Claude.
Our investigation shows that DeepSeek targeted Opus's reasoning traces, exploiting techniques similar to Moonshot's. DeepSeek used reasoning signatures, using the same cross-session replay attack as Moonshot to extract CoT records and bypass our technical controls. DeepSeek used this technique to exfiltrate reasoning traces that would otherwise have been summarized.
DeepSeek rerouted user requests that attempted to use one of its models through third-party or Anthropic coding tools (such as Claude Code, Claude Agent SDK, or OpenCode). DeepSeek inspected various strings contained in inbound requests, flagging users of these third-party tools. Selected flagged users then had their requests forwarded to Claude Opus. This sensitive data may have been routed to Anthropic without the knowledge or consent of DeepSeek's customers.
These cases included: Chinese tech companies. An employee of a Chinese tech company used what they thought was a DeepSeek tool to analyze internal documents. DeepSeek forwarded that data to Claude. The data included sensitive information such as complete specifications for a flagship AI program, organizational structure, and strategic goals. The company almost certainly was not told its data was being forwarded to Claude.
Russian defense agencies. DeepSeek forwarded a request from an IT operator handling data from a Russian government agency linked to the Russian Ministry of Defense. The forwarded request exposed live credentials for a Russian government database.
Chinese public security surveillance. An engineer building a case management system for a Chinese municipal public security bureau used DeepSeek, which forwarded those requests to Claude. The engineer built a tool that matched individuals' movements against police records using national ID numbers.
What AI did in this case
DeepSeek forwarded customer requests to Claude and displayed Claude's responses as its own model's output.
DeepSeek built a CoT extraction pipeline, using a cross-session replay attack to extract Claude's chain-of-thought reasoning records.
DeepSeek flagged users of third-party coding tools and forwarded their requests to Claude Opus.
What the report observed
The report confirmed DeepSeek's routing of customer requests to Claude, as well as the use of a cross-session replay attack to extract CoT records.
The report confirmed that DeepSeek forwarded requests from users of third-party coding tools to Claude Opus.
The report confirmed that forwarded requests contained sensitive data from Chinese tech companies, Russian defense agencies, and Chinese public security surveillance systems.
The report did not confirm whether DeepSeek notified customers that their requests were being routed.
Confirmed & unknown
Confirmed
- The report says DeepSeek built a CoT extraction pipeline, using a cross-session replay attack to extract Claude's chain-of-thought records
- The report says DeepSeek silently forwarded conversations to Claude without notifying customers
- The report says DeepSeek forwarded requests from users of third-party coding tools to Claude Opus
- The report confirmed that forwarded requests contained sensitive data from Chinese tech companies, Russian defense agencies, and Chinese public security surveillance systems
Unknown
- Whether DeepSeek notified customers that their requests were being routed to Claude, the report has not confirmed
- Whether the extracted CoT records were used to train DeepSeek's models, the report does not state
- DeepSeek's response to these allegations, the report does not state
Platform response
Anthropic says it is introducing new methods to strengthen defenses against cross-session replay attacks.
Limits of response:Banning accounts cannot recover the reasoning records already extracted; the report does not state whether DeepSeek has stopped the routing behavior.
Takeaways
- Users may not know their requests are being routed to a third-party model, creating privacy and security risks.
- Cross-session replay attacks can bypass a model's chain-of-thought protections to extract complete reasoning records.
- Forwarded requests may contain sensitive commercial and government data, and leaking them to third parties can have serious consequences.