By TheDailyNewsHub
Chinese artificial intelligence companies DeepSeek and Moonshot AI allegedly routed hundreds of thousands of their customers’ prompts through Anthropic’s Claude AI using fraudulent accounts, in a large-scale effort to extract capabilities from the American AI model.
The revelations are contained in a new threat-intelligence report released by Anthropic, the company behind Claude, which accuses several Chinese AI laboratories of using deceptive methods to obtain large volumes of Claude responses for the development and improvement of their own AI systems.
The companies named in Anthropic’s investigation include DeepSeek, Moonshot AI, Alibaba, Zhipu and Xiaomi, among others. Anthropic says the activity involved millions of interactions with Claude between May and July 2026.
The practice is known as AI model distillation. In legitimate circumstances, distillation allows developers to use a larger model to help create a smaller or more efficient model. But Anthropic says the activity it uncovered involved competitors systematically extracting Claude’s capabilities in violation of its terms of service and access restrictions.
Customers allegedly used Claude without knowing it
One of the most striking allegations concerns the way DeepSeek and Moonshot allegedly handled some customer requests.
According to Anthropic, users who believed they were interacting directly with Chinese AI models were, in some cases, actually having their requests routed to Claude through intermediary services and fraudulent accounts.
Claude would generate the response, which could then be returned to the customer under the Chinese AI company’s service.
This created a potential privacy issue because information entered by customers into the Chinese platforms could be transmitted to Anthropic’s infrastructure without those users necessarily knowing that another AI provider was processing their prompts.
The Wall Street Journal reported that some of the requests contained sensitive information, including passwords and location-related data.
Nearly 300,000 requests in 10 days
Moonshot AI, the company behind the Kimi AI platform, allegedly used a network of thousands of fraudulent accounts to access Claude.
According to reporting based on Anthropic’s investigation, Kimi routed nearly 300,000 customer requests to Claude during a single 10-day period.
Anthropic also said Moonshot generated more than 23 million interactions with Claude between May and July 2026 as part of its broader distillation activity.
DeepSeek, meanwhile, allegedly routed approximately 12.1 million user requests to Claude during the same period, according to reporting on Anthropic’s findings.
The scale of the activity has raised concerns not only about intellectual-property theft but also about the privacy of people using AI services.
Sensitive government and military information allegedly exposed
Anthropic’s investigation reportedly uncovered several particularly sensitive examples among the prompts that were routed through Claude.
One case involved a user allegedly connected to China’s military who asked Kimi to assess whether an individual tracked across hundreds of CCTV cameras in Chengdu was behaving abnormally.
Another reportedly involved live credentials for a Russian government database that were entered into DeepSeek by an IT operator working with data connected to a Russian Defence Ministry-linked organisation.
The Wall Street Journal reported that some of the information transmitted through the Chinese AI services included sensitive location and credential information.
These examples illustrate the potential consequences when users assume they are communicating exclusively with one AI provider while their requests are actually being processed by another company’s model.
DeepSeek allegedly targeted users of coding tools
Anthropic also reported that DeepSeek’s operation went beyond ordinary chatbot interactions.
According to the company’s investigation, DeepSeek identified users running its models through coding tools such as Claude Code and OpenCode and allegedly routed some of those requests to Claude’s more advanced Opus models.
The objective, according to Anthropic, was to collect high-quality responses that could subsequently be used to improve DeepSeek’s own AI systems.
What is AI distillation?
AI distillation is not inherently illegal or improper.
It is a recognised technique in machine learning in which developers use a more capable model to help train another model, often with the aim of producing a smaller, cheaper or more specialised system.
Anthropic itself acknowledges that AI companies routinely use distillation for legitimate purposes.
The controversy arises when a company allegedly uses fraudulent accounts, proxy networks or unauthorised access to obtain another company’s proprietary capabilities at industrial scale.
Anthropic says the Chinese laboratories used thousands of fraudulent accounts and proxy services to circumvent restrictions on access to Claude, which is not commercially available in China.
Anthropic says the campaigns were detected
Anthropic says it identified the activity through patterns in account behaviour, request metadata, IP addresses, payment information and other infrastructure indicators.
The company said it has since banned suspicious accounts, strengthened verification requirements and introduced additional measures to detect large-scale distillation attempts.
Anthropic previously disclosed in February that DeepSeek, Moonshot and MiniMax had generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.
The latest disclosure suggests that the scale of the activity subsequently became substantially larger, with Anthropic now reporting hundreds of millions of interactions involving several Chinese AI laboratories.
China rejects US accusations
The allegations come amid growing tensions between Washington and Beijing over artificial intelligence technology.
Chinese authorities have rejected broader American accusations that Chinese AI companies are conducting malicious or industrial-scale efforts to extract capabilities from U.S. AI models.
China’s Commerce Ministry described the accusations as groundless and accused the United States of attempting to monopolise AI development.
The companies named in Anthropic’s latest report have not all publicly responded to the specific allegations.
Growing AI security concern
The dispute highlights a rapidly developing problem in the global AI industry: as models become more capable, competitors have strong incentives to obtain their capabilities without spending the same amount of time and money developing them independently.
But the alleged routing of real customer requests introduces a separate concern — privacy.
Users typically expect that when they submit sensitive information to an AI service, they know which company is processing that information. If prompts are secretly redirected to another provider, that expectation can be undermined.
For businesses and government organisations, the risks could be even greater if employees inadvertently enter passwords, confidential documents, personal information or sensitive operational data into an AI platform.
Anthropic’s findings therefore raise questions that extend beyond the competition between American and Chinese AI companies.
They also highlight the need for AI providers to be transparent about where user data is processed, which models handle customer requests and what happens to information submitted through third-party platforms.
As the global AI race accelerates, the latest allegations demonstrate that the competition is no longer simply about building better models. It is increasingly also about controlling access to data, protecting intellectual property and ensuring that users know exactly where their information is going.
