Illicit model distillation · GTG-16002
Report's allegations about Moonshot request routing: GTG-16002 case
This page is a Chinese-to-English translation of content from pages 148–149 of Anthropic's September 2026 report. All content involving specific companies is Anthropic's unilateral allegation; this site has not independently verified it, and it does not constitute a finding of illegality.
According to the Anthropic report, Moonshot (the developer of the Kimi models) silently forwarded customer requests to Claude and then displayed Claude's responses to users, who thought they were using Kimi. In one ten-day window, nearly 300,000 customer requests were forwarded, the vast majority to Opus; the proxy network had 5,380 fake accounts. The report did not confirm whether users were aware. All of the above are the publisher's allegations, not this site's independent findings, and not a judicial conclusion.
What happened
We found that Moonshot AI (the company that produces the Kimi series of models) silently forwarded customer requests to Claude instead of processing them with Kimi. Moonshot then displayed Claude's responses to users. These users thought they were using the Kimi model but were actually receiving Claude's responses.
In one instance, over ten days, Moonshot forwarded nearly 300,000 customer requests to Anthropic, the vast majority of which were routed to Opus. Moonshot used a proxy service network of 5,380 fraudulent accounts, most of which appeared to be located in Singapore and Japan.
In addition to providing Claude's responses to customers, Moonshot also captured and saved at least some of these conversations. Moonshot built a CoT extraction pipeline to extract Claude's CoT records from the saved forwarded conversations to train its models. Moonshot also extracted CoT records collected through other means.
When responding, Claude returns a reference to its original thinking as a 'thinking signature' rather than the original thinking, to reduce the risk of unauthorized distillation. Our API uses this reference to look up the original thinking trace in subsequent API calls. Moonshot was able to bypass this control and extract these reasoning traces by saving the thinking signature from Claude's response, starting a new session, and inducing Claude to convert the thinking signature back into the full reasoning trace. These cross-session replay attacks enable entities responsible for illicit distillation to collect CoT reasoning records. We are introducing new methods to strengthen defenses against these tactics.
Our investigation also shows that user queries rerouted to Claude by Moonshot contained sensitive information about various Moonshot customers. We do not know whether Moonshot notified its customers that their requests were being rerouted to Anthropic and exposed to third parties.
These included: PLA-linked surveillance activity. A user we assess may be linked to the PLA used what they thought was Moonshot's Kimi model to load surveillance data from CCTV footage of a single target individual. The user asked Kimi to analyze the CCTV data to understand whether the person being tracked was behaving abnormally. The CCTV data included video surveillance from hundreds of cameras in Chengdu, including cameras outside PLA facilities, institutions linked to China Electronics Technology Group Corporation, and a large state-owned enterprise.
What AI did in this case
Moonshot forwarded customer requests to Claude and displayed Claude's responses as Kimi's output.
Moonshot built a CoT extraction pipeline to extract Claude's chain-of-thought reasoning records from the forwarded conversations.
Moonshot used a cross-session replay attack to bypass Claude's thinking signature protection and extract full reasoning traces.
What the report observed
The report confirmed Moonshot's routing of customer requests to Claude, as well as a forwarding volume of nearly 300,000 requests over ten days.
The report confirmed that Moonshot captured and saved conversations and built a CoT extraction pipeline.
The report confirmed that user queries contained sensitive information, including PLA-linked surveillance activity.
The report did not confirm whether Moonshot notified customers that their requests were being routed.
Confirmed & unknown
Confirmed
- The report says Moonshot silently forwarded customer requests to Claude rather than processing them with Kimi
- The report says nearly 300,000 customer requests were forwarded over ten days, the vast majority to Opus
- The report says Moonshot used a proxy network of 5,380 fraudulent accounts
- The report says Moonshot built a CoT extraction pipeline to extract Claude's chain-of-thought reasoning records
Unknown
- Whether Moonshot notified customers that their requests were being routed to Claude, the report has not confirmed
- Whether the extracted CoT records were used to train the Kimi models, the report does not state
- Moonshot's response to these allegations, the report does not state
Platform response
Anthropic says it is introducing new methods to strengthen defenses against cross-session replay attacks.
Limits of response:Banning accounts cannot recover the reasoning records already extracted; the report does not state whether Moonshot has stopped the routing behavior.
Takeaways
- Users may not know their requests are being routed to a third-party model, creating privacy and security risks.
- Chain-of-thought reasoning records are a model's core asset; cross-session replay attacks can bypass protections to extract these records.
- User queries may contain sensitive information, and forwarding them to third parties can lead to data leaks.