Anthropic says Moonshot routed Kimi user requests through Claude

Anthropic alleges Moonshot sent nearly 300,000 Kimi customer requests primarily to Claude Opus through 5,380 fraudulent accounts.

By · Published

Primary source: Bloomberg Technology

Why it matters

Moonshot is asking US clouds, developers and investors to trust Kimi as an independent model platform. Anthropic's claim puts model provenance and user-request handling at the center of that sale.

A glowing holographic interface streams electric-blue data into a dark, monolithic server stack in a high-tech setting, depicting unseen connections.

Yang Zhilin's Moonshot AI routed Kimi user requests through Anthropic's Claude models without telling those users, Anthropic alleged in a Bloomberg report published September 10th. Anthropic said it identified one cluster of nearly 300,000 requests, sent primarily to an Opus model through 5,380 fraudulent accounts that mostly appeared to operate from Singapore and Japan.

The claim reaches the core of what Yang is selling. Moonshot presents Kimi as its own assistant and agent platform, powered by its own model family. If Kimi passed ordinary user prompts to Claude and displayed the answers as Kimi's work, the dispute extends beyond how Moonshot trained its models. It raises a direct question about which model was handling a user's data and producing the product's output.

Yang entered the AI race with a substantial research record. He earned a Ph.D. in computer science from Carnegie Mellon University in 2019 after studying at Tsinghua University, and co-authored the Transformer-XL and XLNet papers. He also worked with researchers at Meta AI and Google Brain before founding Moonshot in Beijing in 2023.

Moonshot released Kimi K3 in July, a 2.8-trillion-parameter mixture-of-experts model. RuntimeWire previously reported that Moonshot launched K3 on July 16th and released its weights on July 27th. Moonshot later began seeking up to 30% of revenue generated from K3 services on Azure, AWS and Google Cloud, an effort to turn open weights into a recurring enterprise distribution business.

Anthropic's accusation therefore lands as Moonshot expands Kimi beyond its own product into cloud distribution.

What Anthropic has alleged

Distillation itself is a standard training method. A developer can use responses from a larger model to train a smaller or cheaper one, including when a model provider distills its own systems. Anthropic's allegation concerns the alleged use of false accounts, proxy infrastructure and restricted Claude access to collect training data from a competitor at scale.

The product-routing claim sits within a broader distillation allegation. In a public report published Thursday, September 10th, Anthropic said Moonshot generated more than 3.4 million exchanges with Claude through hundreds of fraudulent accounts. Anthropic said the prompts focused on agentic reasoning, tool use, coding, data analysis, computer-use agents and computer vision.

Anthropic attributed that campaign to Moonshot using request metadata that Anthropic said matched public profiles of senior Moonshot personnel. Anthropic also claimed a later phase attempted to reconstruct Claude's reasoning traces. Those are Anthropic's findings, and the available public record does not independently establish that Kimi's consumer product forwarded user prompts to Claude.

Bloomberg's September 10th account describes that specific allegation. Its figures cover a narrower apparent slice of the activity: nearly 300,000 requests and 5,380 accounts, compared with more than 3.4 million exchanges and hundreds of accounts across the broader campaign described by Anthropic. The timing of the alleged traffic remains unestablished, so the available record does not tie it to K3 or another particular Kimi release.

Bloomberg also reported that Anthropic accused DeepSeek and Xiaomi of similar conduct. Anthropic's report named DeepSeek and MiniMax alongside Moonshot, indicating that the accounts concern different sets of alleged campaigns.

A model dispute becomes a product dispute

AI products routinely route requests among models for cost, speed or reliability. That practice depends on disclosure, valid access and agreements governing how user data is processed. Anthropic alleges Moonshot concealed the routing while using accounts created to evade Anthropic's regional restrictions.

Anthropic says it does not allow its technology to be accessed from inside China. According to Bloomberg, most of the 5,380 accounts associated with the alleged Moonshot traffic appeared to be in Singapore and Japan. Anthropic's report described proxy operators maintaining pools of accounts and replacing them when individual accounts were blocked.

For Kimi users, the model-training argument is secondary to provenance. A user choosing Kimi may be selecting Moonshot because of its price, open-weight model strategy or technical characteristics. Undisclosed Claude routing would mean the response came from a different provider with its own data-handling rules and safety systems.

The allegation also complicates Moonshot's international distribution push. Together AI said in July that it would host K3 and future Moonshot open-weight releases on US infrastructure. Cloud and inference partners need confidence that the capabilities they are marketing can be traced to the weights and technical materials Moonshot supplies.

The fight over who paid for the intelligence

Anthropic has a commercial stake in defining large-scale competitive distillation as illicit extraction. Anthropic spent heavily to develop Claude and sells access through closed products and APIs. A rival that obtains similar capabilities from Claude outputs could avoid part of that research and compute bill while undercutting Anthropic on price.

Anthropic has paired that commercial argument with a national security case. Its September report explicitly backed US export controls and argued that distillation allows Chinese developers to close capability gaps while bypassing restrictions. On September 8th, the NSA, FBI and CISA issued a joint warning accusing China-based AI developers of industrial-scale campaigns against American models.

That government support gives Anthropic's framing weight in Washington, where accusations against Moonshot have already moved from an intellectual-property dispute toward possible trade restrictions. RuntimeWire reported in July that US officials were using distillation allegations to support threats of sanctions against Chinese AI developers.

Moonshot has substantial capital riding on Yang's ability to keep selling Kimi as original technical work. TechCrunch reported in May that Moonshot raised about $2 billion at a $20 billion valuation in a round led by Meituan's Long-Z Investments, with Tsinghua Capital, China Mobile and CPE Yuanfeng participating. The report, citing a financial adviser involved in the transaction, put Moonshot's annual recurring revenue above $200 million in April from subscriptions and API use.

Yang's research record and Moonshot's engineering output remain part of the record. Anthropic's allegation changes the diligence question for every customer and backer evaluating Kimi: how much of the capability came from Moonshot's research, and how much may have been acquired through access to competing models? The product-routing claim makes that question visible at the level users can see - the answer appearing on their screen.

Reader comments

Conversation for this story loads after sign-in.