What Anthropic says happened
Anthropic says Moonshot redirected users' questions away from its own Kimi system without telling them, then showed Claude's responses as if they were Kimi's. The company says it traced close to 300,000 customer requests that were sent to its systems, most of them hitting Anthropic's Opus model. Because Anthropic blocks access from within China, it says Moonshot relied on 5,380 bogus accounts to get in, with most appearing to be set up in Singapore and Japan.
Anthropic frames the behavior as distillation, where a developer taps responses from a stronger model to boost a weaker one. In this case, Anthropic says it believes the answers Moonshot got from Anthropic's models were repurposed to train Moonshot's own software. It further alleges that DeepSeek and Xiaomi Corp. pursued comparable tactics.
The report and the examples it contains
Anthropic's 145-page report maps out threats involving its software that it says it detected and disrupted from last December through August. The list, the company says, spanned suspected state-sponsored and financially motivated cyberattacks, as well as surveillance efforts and disinformation campaigns. In one case, a Kimi user submitted Chinese surveillance footage seeking an assessment of whether a particular individual was acting out of the ordinary.
While the user likely assumed that request would go to Moonshot, Anthropic says it reached one of its own models, making the content visible to the US firm. The upload included video feeds from hundreds of cameras, including ones outside People's Liberation Army facilities.
The company says its case studies show AI speeding up malware development, expanding social media monitoring and amplifying political propaganda. Anthropic says it blocked the abusive accounts and added safeguards to curb repeat attempts.
Protecting your savings means steady habits and a long view on risk. Join Briefs Finance CEO Jaspreet Singh on September 29th for a FREE live investor workshop, How to Profit From A Dollar That's Losing its Value, where he shows how we're spotting investment opportunities as the dollar falls. Save your spot.
The company also said Wednesday that, during security testing, it uncovered another hacking incident carried out by one of its models. Anthropic added that the episode concerned an early build of Claude Opus 4.6.
Wider pushback and reactions
Jacob Klein, Anthropic's head of threat research, says distillation is a common technique, and even Anthropic has seen gains when distilling its own models. But he cautions that when this is done without permission, competitors can cut corners and sell stronger systems for less, a dynamic that could squeeze Anthropic and peers as the company moves toward an IPO. He added, "If we were to do that, or if one of our competitors would do that, that would be a large privacy scandal."
The report was published shortly after US security agencies alleged that leading Chinese AI firms - among them DeepSeek and Moonshot - were systematically taking proprietary expertise from American developers via distillation, and they urged Silicon Valley to better secure their work. Previously, US tech firms - including Anthropic - had charged Chinese companies, Moonshot included, with practicing distillation. Since then, Moonshot has risen to the front rank in China, helped by a summertime spike in interest in its Kimi K3 model.
Moonshot declined to provide a comment. DeepSeek and Xiaomi representatives failed to respond to inquiries for comment submitted outside normal business hours. China's Commerce Ministry said there is "no factual or legal basis" for claims that Chinese AI firms are conducting industrial-scale distillation of US models and warned it would take countermeasures if the US "takes action to contain and suppress" Chinese AI companies.
What this could mean for your portfolio
This fight is about more than whose chatbot sounds smarter. It is about who owns the training data, how safely it is handled and whether gray-zone tactics translate into lower costs. Anthropic's account includes very tangible spillover, like sensitive surveillance footage ending up with a US company, plus business pressure as it gears up to go public.
For everyday investors, the signal is clear: in AI, security, data flows and trust are business fundamentals. Anthropic's 145-page report and its note about a hack discovered during Opus 4.6 testing show how technical risks can quickly become reputational, affecting pricing power and growth paths.
A simple plan can help your money grow while you sleep and adapt. Our CEO Jaspreet Singh is hosting a FREE live investor workshop, How to Profit From A Dollar That's Losing its Value, on September 29th. Sign up free to join him live.
