Anthropic accuses Moonshot of serving Claude instead of Kimi: what the report proves (and what it doesn't)
Anthropic accuses Moonshot AI, the company behind Kimi, of secretly relaying customer requests to Claude and showing the answer as if it came from Kimi. The accusation is in a report dated September 10, 2026, and Moonshot has not answered it yet.
In practice: you call the Kimi API, you get a response, you pay Moonshot's invoice. And, according to Anthropic, for at least one ten-day period the model that actually answered was Claude Opus.
This is the heaviest accusation a US lab has made against a Chinese lab so far, and it is different from everything that came before. It is not just "they trained on our outputs". It is "they took the customer's request, sent it to our model behind the scenes and returned the answer under a different label". In this post we separate what Anthropic actually wrote, what the press inflated, what nobody has proven yet and what changes for anyone running Kimi in production.
TL;DR
- What it is: on 2026-09-10 Anthropic published a 154-page report accusing Moonshot AI of relaying Kimi customer requests to Claude and displaying the answer as if it were Kimi's.
- The report's numbers: almost 300,000 requests in ten days, the "vast majority" to Opus, with a network of 5,380 fraudulent accounts. Over 23 million exchanges attributed to Moonshot between May and July.
- What's missing: logs, account lists, which Kimi product was affected, what share of traffic. No third party has verified the relay.
- Moonshot's response: as of 2026-10-06, no public statement about the relay.
- Primary source: Anthropic's report (PDF), "Illicit distillation" section, pages 143 to 154.
Anthropic vs Moonshot: two accusations, not one
Almost all coverage blends the two. Don't, because they rest on different evidence.
Accusation A: distillation. Moonshot allegedly created fake accounts in bulk to collect Claude responses and use them as training data for Kimi. This one is old. It came out on 2026-02-23, in the post Detecting and preventing distillation attacks, which named DeepSeek, Moonshot and MiniMax: over 16 million exchanges through roughly 24,000 fraudulent accounts. Moonshot's share was "over 3.4 million exchanges", attributed through request metadata that, according to Anthropic, matched the public profiles of senior Moonshot staff.
Accusation B: live relay. This is the new one, and it is what justifies the "Claude behind the scenes" headline. It is case GTG-16002 in the September report, whose title says it all: "Moonshot serves Claude instead of Kimi and collects exchanges for model training". The core passage, on page 148:
"We discovered that Moonshot AI, the company that produces the Kimi family of models, silently forwarded customer requests to Claude, instead of processing them using Kimi. Moonshot then displayed Claude's responses to users. These users thought they were using a Kimi model, but received responses from Claude instead."
And the number:
"In one instance, over a ten-day period, Moonshot relayed almost 300,000 customer requests to Anthropic, the vast majority of which were routed to Opus."
According to the South China Morning Post, this was the first time Anthropic accused Chinese companies of rerouting users directly to Claude. The report names seven labs in total: Alibaba, Moonshot, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax.
Notice the detail that changes the reading. Anthropic does not describe Kimi as a permanent Claude wrapper. It frames the relay as a collection channel: pushing real user traffic into Claude produces exactly the kind of data that is gold for training, which is real conversations, with real tool calls, on real problems. No synthetic dataset comes close.
This is where the story stops being geopolitical gossip and becomes an engineering problem. If all you know is how to swap the model variable and hope, you have no way to notice something like this. If you have evals running, traffic routed deliberately and sensitive data masked, you notice, or at least you limit the damage. That is the bar we hold every week at Clã Beer and Code, our Portuguese-speaking community: if you depend on the tool and don't understand what runs behind it, the place will make you uncomfortable.
Timeline of the case
| Date | What happened |
|---|---|
| 2026-02-23 | Anthropic accuses DeepSeek, Moonshot and MiniMax of distillation. Moonshot: over 3.4 million exchanges. |
| 2026-07-16 | Moonshot launches Kimi K3. Users post the model saying it is Claude. |
| 2026-07-21 | Moonshot's Huang Zhenxin says K3 "is not a distilled copy of any existing model". |
| 2026-07-22 | Michael Kratsios, of the White House, says on X that Moonshot distilled Fable to build K3. |
| 2026-07-27 | K3 weights are released. |
| 2026-08-10 | The paper Stealing Reasoning Traces from Proprietary LLM APIs shows reasoning signatures can be replayed across sessions. |
| 2026-09-08 | NSA, CISA and FBI publish joint advisory AA26-251A naming Moonshot. |
| 2026-09-10 | Anthropic publishes the report with case GTG-16002. First relay accusation. |
| 2026-09-12 | Moonshot posts a Weibo statement about rumours involving its founder. It does not mention Anthropic. |
| 2026-09-22 | The Information reports that China's regulator (CAC) is investigating DeepSeek and Moonshot. |
| 2026-09-30 | OpenAI says it disrupted a reasoning-extraction campaign with a core cluster linked to Moonshot. |
| 2026-10-06 | Moonshot closes a round at a US$50 billion valuation, targeting a Hong Kong IPO. |
We covered the July stage in US threatens to sanction Chinese open-source AI and the OpenAI one in our post on PewDiePie's ban and distillation (both in Portuguese).
How the relay would work: thinking signatures and replay
The first technical objection that showed up on Hacker News is a good one. Kimi shows its full reasoning. Claude hides it. So swapping one for the other should be obvious. In the words of a user in the thread about the report:
"I don't even see how that would work since you see the full thinking traces in Kimi but are hidden with Claude."
Anthropic's answer is in the report itself. When Claude reasons, the API returns a thinking block with a signature, which you send back on later turns to keep continuity. According to Anthropic, Moonshot got around that control like this:
"...by saving the reasoning signature from Claude's response, starting a new session, and eliciting Claude to convert the reasoning signature back into the full reasoning trace."
The report calls this a "cross-session replay attack". It is not fiction: the August paper, published a month earlier, demonstrated the same class of flaw across several providers.
The fix is already in the API. The preserved thinking docs describe that, starting with Claude Fable 5.1, a thinking block is only usable if the model is compatible and nothing before it in the conversation has changed. Sonnet 5.5 added account binding: a block coming from another account is silently dropped.
In product terms: if you store thinking blocks and rebuild history (changing the system prompt, reordering tools, compacting old messages), those blocks are now ignored. Worth checking your harness.
What the report does not prove
This is the part the hype skipped.
It does not say all of Kimi is Claude. The only relay figure is one ten-day instance, with almost 300,000 requests. No dates, no share of traffic.
It does not say which product. Consumer app? API? Kimi Code? The text only says "customer requests". The "Kimi app" that appears in some articles is press wording, not Anthropic's.
The 23 million are not 23 million relays. The report labels the number as "scale of distillation attacks attributable to Moonshot between May and July 2026". It is the total for the distillation activity. It does not say how much of it was relayed user traffic. Some outlets treated all of it as user input sent to Claude.
The 5,380 accounts appear in a separate sentence. The text does not explicitly tie those accounts to the 300,000 requests.
The tactic of tagging Claude Code users is DeepSeek's, not Moonshot's. The report describes DeepSeek checking strings in requests to identify users of Claude Code, the Claude Agent SDK and OpenCode, and relaying some of them to Opus. That mechanism is not attributed to Moonshot.
There is no published evidence. No logs, no account lists, no specific attribution method beyond "high confidence". The indicators file that accompanies the report contains nothing from case GTG-16002. Anthropic is an interested party and controls the telemetry. That does not make the accusation false. It makes it unverified.
And there is an economic argument nobody has answered well: why pay Opus prices to serve a customer who pays you Kimi prices? The only answer that adds up is Anthropic's own. The goal would not be to serve, it would be to collect.
Do not just follow the news — master it. Hands-on AI Engineering, live, every week, in the largest community in Brazil.
Join the ClãWhat about Kimi K3 being distilled from Fable?
That is a third accusation, and it is not Anthropic's.
It came from the US government. First Kratsios on X, on July 22. Then advisory AA26-251A, which says Moonshot "extracted significant Claude Fable 5 data to train its Kimi-K3 model". Anthropic's report never mentions K3, and the only Fable distillation case it describes is an abandoned attempt by Zhipu.
Independent researchers were doubtful. Braden Hancock, to TechCrunch:
"Fable's only been publicly available since July 1st. You can't distill that much data, train a model, and release it in two weeks."
And the behavioural evidence? It exists, but it is weak. An experiment in Ryan Greenblatt's repository found K3 identifying itself as Claude in 7 of 48 neutral probes and emitting IDs such as claude-opus-4-5-20251101. But the write-up itself warns that it was produced entirely by an AI agent, without human verification, and concludes that behaviour alone cannot distinguish deliberate distillation from training on a corpus saturated with Claude transcripts. And the IDs point to the 4.5 generation, not to Fable.
A model saying it is another model is a symptom of training data. It is not proof of a proxy.
What Moonshot said
About the relay: nothing, as of this post.
Bloomberg recorded that the company did not immediately respond. The only public statement after the report came on September 12 and denies rumours about the founder and employees, saying the company filed a police report. It mentions neither Anthropic, nor Claude, nor routing. Headlines saying "Moonshot denied it" read more than was written.
What does exist are older denials about distillation: Huang Zhenxin's in July, and the explanation, in a January AMA reported by VentureBeat, that K2.5 called itself Claude because of recent coding data in pretraining.
The most curious development came from inside China. According to The Information, as relayed by TNW, the Chinese regulator summoned all seven labs and zeroed in on DeepSeek and Moonshot. The reason is the mirror image of the American narrative: Chinese user data ending up at a US company. The report cites two examples, including an engineer who exposed internal code and live credentials from major Chinese companies. Single source, anonymous, no official announcement. Treat it as reported, not confirmed.
What changes if you run Kimi in production
Three practical questions.
1. Where does your request go?
The alleged relay happens on Moonshot's servers. Open weights running on a third-party host are a different risk profile. The GitHub changelog says K3 in Copilot is "hosted by GitHub on Fireworks AI". That this falls outside the reach of the relay is our inference, not a statement by GitHub or Anthropic. But it is a reasonable one: the request never touches Moonshot's infrastructure.
If you use OpenRouter, you can pin the provider instead of letting the router choose:
{
"model": "moonshotai/kimi-k3",
"provider": {
"only": ["fireworks", "together"],
"allow_fallbacks": false,
"data_collection": "deny"
},
"messages": [{ "role": "user", "content": "..." }]
}
Check the provider slugs on the model page before copying, because the list changes.
2. What are you sending?
The report says the relayed traffic contained internal code and live credentials. Whoever is right in this fight, the lesson is old: secrets do not go in prompts. Scoped keys, rotation, masking customer data before the call. That applies to any provider, from any country.
3. Does the math still work?
| Model | Input (US$/1M) | Output (US$/1M) |
|---|---|---|
| Kimi K3 | 3.00 | 15.00 |
| Claude Sonnet 5.5 | 2.00 | 10.00 |
| Claude Opus 5.5 | 4.00 | 20.00 |
| Claude Fable 5.1 | 10.00 | 50.00 |
Sources: Moonshot and Anthropic, checked on 2026-10-06. K3 is 25% cheaper than Opus 5.5 and 50% more expensive than Sonnet 5.5. The "it's much cheaper" argument is not what it was in July, when we ran the numbers on Kimi K3 versus Claude (in Portuguese).
Limitations and caveats
- Everything about the relay comes from a single source: Anthropic. The accusation may be true and still is not publicly proven.
- The Chinese regulator's investigation rests on a single anonymously sourced story.
- OpenAI's September 30 post is about extracting reasoning from its own models, not about proxying. According to CyberScoop, it presented no technical evidence for the attribution. It is not independent corroboration of the relay.
- We found no Anthropic lawsuit, no sanction imposed and no Entity List designation. These are negative search results, not confirmed facts.
- We found no provider or tool that removed Kimi after the report.
- Anthropic itself writes, in the February post, that distillation is "a widely used and legitimate training method". The fight is about doing it with fraudulent accounts and against the terms of service.
Quick FAQ
Is Kimi just a Claude wrapper? That is not what Anthropic claims. It alleges that Moonshot relayed part of its customer traffic to Claude, with one quantified case of almost 300,000 requests in ten days, and used those exchanges for training. The report does not say all of Kimi runs on top of Claude.
Did Moonshot deny it? Not publicly, as of 2026-10-06. The denials on record are about distillation and predate the September report. The September 12 statement is about rumours concerning the founder.
Is using Kimi K3 now illegal? No. No sanction has been imposed and there is no blocking order. The risk today is continuity and compliance: the US Congress has already sent letters to companies using Chinese models, such as Cursor's parent company and DoorDash.
Does running the open weights solve it? It solves the relay part, because the request does not go through Moonshot. It does not solve the debate over where the training data came from, nor the clauses in K3's licence. We break down the cost of running it in Kimi K3 released its open weights (in Portuguese).
Conclusion
There is a serious accusation, made by the party that holds the telemetry and has not shown it. There is an accused that stayed quiet. And there is a Chinese regulator apparently more worried about the data that leaked than about the national lab's honour.
What can be said today: Anthropic says Moonshot served Claude instead of Kimi during at least one ten-day window. What cannot: that this was verified, that it hit the API you use, or that K3 is Fable in disguise.
The lesson does not depend on the verdict. A model endpoint is a black box with a name on the front. You cannot audit what runs behind it, so you control what goes in, measure what comes out and choose where it passes through. If you want to know how labs detect this kind of extraction and where the line sits between legitimate synthetic data and a ban, the next step is our post on distillation and the Ajax case (in Portuguese).
{AI Engineer} — apaixonado por Laravel, arquitetura de software e construir produtos com impacto. Compartilho aqui tutoriais, descobertas e reflexões sobre o dia a dia de engenharia.
There is no shortage of content. What is missing is someone to untangle it: what matters now is how to implement it the right way. In the Clã you get that live, every week, with people who have already filtered out the noise.
Join the Clã