📁 CASE FILE 02 — THE RELAY Subjects: Moonshot AI (Kimi) · DeepSeek · Alibaba · Anthropic (accuser) Period: May – July 2026 · Report published 10 September 2026 Status of central claim: 🟢 alleged with telemetry by the accuser · 🔴 denied by the accused · 🟡 never independently audited Companion file: Case File 01: The Trojan Horse
Part two of a two-part dossier. Confidence tags: 🟢 verified · 🟡 unproven · 🔴 denied. We covered the news of this report when it dropped; this file is about what it means, and what it proves about File 01.
In Case File 01, two mathematicians suspected their private work had flowed into a rival’s model, and the company involved could not rule it out. Nothing about that case can be audited by anyone outside the company.
This file is the mirror image — and it cuts both ways. Anthropic’s September threat-intelligence report alleges that Moonshot AI, maker of Kimi, silently rerouted real customer requests to Claude and showed users Claude’s answers as if they came from Kimi. The claims rest on telemetry only Anthropic can see. But one fact in the report is verifiable from Anthropic’s own side of the wire, and it is the fact that matters most to ordinary users: other people’s private conversations ended up on Anthropic’s servers, and those users never chose that.
Exhibit A: The relay 🟢 alleged, with specifics · 🔴 denied
Anthropic’s case file designation is GTG-16002. Between May and July 2026, it alleges, Moonshot forwarded nearly 300,000 real Kimi customer requests to Claude over a ten-day stretch — most of them to Opus, the most capable model in Anthropic’s lineup — through a proxy network of 5,380 fraudulent accounts, most appearing to be located in Singapore and Japan. Users believed they were talking to Kimi. Across May to July, Anthropic attributes more than 23 million exchanges to Moonshot.
The report also describes a training pipeline: Claude’s answers and reasoning traces were saved, then replayed across fresh sessions to make the model convert its own “thinking signatures” back into full reasoning transcripts — a workaround for Anthropic’s anti-distillation controls.
Moonshot’s position: 🔴 denied. It rejected the distillation characterisation in July, and on 12 September it called the detention rumours (more on those below) “entirely fabricated” and filed a police report. Notably, it has not disputed that some requests were relayed — it disputes what the relaying was for. China’s Ministry of Commerce calls distillation “essentially a neutral technical approach used by model developers around the world, including US companies.” That framing contests the characterisation, not the technique.
Exhibit B: What the relayed chats contained 🟢 per the accuser’s own logs
This is the part of the report that outlives the geopolitics. Among the requests rerouted to Anthropic’s servers, the report describes:
- CCTV surveillance footage from hundreds of cameras in Chengdu, including cameras near PLA facilities, submitted by a user Anthropic assessed as likely military-connected — who was using Claude, apparently without knowing it, to check whether tracked individuals showed “abnormal behaviour”
- internal code and live credentials from major Chinese companies
- live credentials for a Russian government database
🟡 The scale and attribution are Anthropic’s claims alone. 🟢 But the data’s arrival is not something the accused can dispute away: if the relay happened at all, the data is on Anthropic’s servers. The report concedes it does not know whether any of those users were ever told their data had left the country. Beijing has called the report a smear; it has not explained why, if the report is fabricated, its description of Chinese users’ data on US servers should be dismissed rather than investigated.
Read those two facts together and the irony is complete: Chinese military surveillance data leaked to a US AI company through a pipeline built to extract value from that same US company. The distillation pipeline and the data-leak pipeline were the same pipeline.
Exhibit C: The rumour cycle 🔴 denied, instructive anyway
Within two days of publication, Chinese social platforms were carrying a claim that Moonshot founder Yang Zhilin and 15 executives had been taken away for investigation. A Chinese-language finance account on X with a blue check packaged the rumour with editorial garnish — the founders of Kimi and DeepSeek described as amateurs who “didn’t even know they’d been caught” — and it collected 1,500+ likes. Its attached “evidence” was a screenshot of someone else posting the same rumour.
Moonshot called the detentions entirely fabricated on 12 September and filed a police report. No major outlet has confirmed any detention. 🟡 what the vacuum proves: when a story this sensitive breaks with no verifiable detail, the information vacuum fills with rumour dressed as reporting within 48 hours. The verified core of this story — relayed requests, exposed data — was strong enough on its own. The rumour added nothing but risk.
Exhibit D: The scale, and the accuser’s asymmetry 🟡
Moonshot is not the biggest name in the report — it is the most legible. Alibaba allegedly ran the largest operation: more than 151 million Claude queries through 3,500 accounts, a follow-up to a 28.8-million-query campaign Anthropic flagged in June. DeepSeek allegedly tagged incoming requests containing Claude Code strings and relayed them — 12.1 million exchanges in the first two weeks of July alone. Seven China-based labs are named in total; a CISA/NSA/FBI advisory issued 8 September, two days before the report, names six and describes the campaigns as industrial-scale, “likely with Chinese government awareness.”
Now the caution, and it is the same caution File 01 taught — pointed the other way. Every number in this file comes from the accusing party’s own investigation, published by the company that says it was harmed, two days after its own government escalated the same dispute. No independent body has examined the evidence. The US advisory is built on the same industry reporting pipeline.
And there is a symmetry the AI industry would rather nobody noticed: in the Buckmaster case, the Anthropic researcher Levent Alpöge was on the other side of the table — the collaborator whose authorship OpenAI reportedly offered to scrub. Anthropic accuses Chinese labs of industrial-scale extraction of its models; OpenAI stands accused of something adjacent with private researcher data. Both companies’ positions rest on evidence only they can audit. Neither case survives contact with the question “who checked?”
Confidence ledger — File 02
| Claim | Status |
|---|---|
| Anthropic published the report and the telemetry behind it | 🟢 Verified |
| Users’ private data (CCTV footage, code, credentials) reached Anthropic’s servers | 🟢 Verified per accuser’s own systems — the one fact the accused cannot easily reverse |
| Moonshot relayed 300K+ requests and ran CoT-extraction pipelines | 🔴 Denied by Moonshot · 🟡 Anthropic’s telemetry only |
| Chinese government directed the campaigns | 🟡 US advisory’s assessment, same reporting pipeline, no independent check |
| Detentions of Yang Zhilin and executives | 🔴 Denied by Moonshot, police report filed, no independent confirmation |
The provenance problem — the part that matters in New Zealand
Strip the geopolitics and File 02 is about one question: when you type into a branded assistant, which model actually answers?
In the alleged Moonshot case, paying customers of one product were silently served another company’s model. If that can happen once — and this is the one case on record where telemetry caught it — procurement, privacy and evaluation claims built on model identity all break. A business that chose Kimi for price, or data-residency reasons, or contractual reasons, did not get Kimi. Its prompts went to a US company it had no relationship with, under a brand it never contracted with. Model provenance stops being a benchmark footnote and becomes a vendor-management question: which model answered, under which terms, with whose data.
For New Zealand the practical version is unglamorous. Businesses and agencies buying AI should be adding provenance clauses: which model answers, is any request ever forwarded to a third party, where does the data land. That is not paranoid — it is the documented failure mode. And it strengthens the argument we made in the sovereign AI build from the other direction: owning the stack matters, but File 02 shows the deeper issue is auditability of the interface. A locally-hosted open-weight model is auditable in a way a foreign closed API with a relay scandal in its history simply is not. This is also, quietly, an argument for the open-weight ecosystem — xAI’s admitted distillation of OpenAI models in the Musk–Altman trial filings and Beijing’s “neutral technical approach” defence both point the same way: everyone distils; the only variable is disclosure. An open model can be inspected. A closed one can only be trusted.
Case assessment — both files, one problem
Put the two files side by side and the shape of the problem is finally visible.
File 01: your ideas flow in. Unproven, unprovable — the accusers are two mathematicians, the evidence is circumstantial, and the company cannot rule it out.
File 02: your prompts flow out. Alleged with telemetry by the company on the receiving end, denied by the accused, auditable by no one else.
The chat-input stage of the AI economy has no audit trail in either direction. In one case the suspicion is unverified; in the other, the verification belongs entirely to an interested party. Both cases were broken open by outsiders — a mathematician who published his emails, a company that published its own logs — not by auditors, regulators, or the vendors’ own disclosure. That is not a functioning trust system. That is two companies catching each other.
The defence is behavioural, and it is the same in both files: treat the chat box as untrusted infrastructure. Published work, or work you are happy to donate, goes in. Crown jewels do not. Institutions should say it out loud. And whoever answers when you type — read the provenance question as seriously as the price.
← Missed Case File 01: The Trojan Horse? Start there.
❓ FAQ
Is the Moonshot relay confirmed? No. The claims come from Anthropic’s threat-intelligence report and are repeated in a US government advisory built on the same reporting. Moonshot denies them, and no independent body has examined the evidence. The verifiable part is that users’ private data reached Anthropic’s systems.
Were Moonshot executives detained? Moonshot says the detention rumours are entirely fabricated and has filed a police report. No major outlet has confirmed any detention. The rumour spread to 1,500+ likes on X within two days of the report.
What is distillation? A legitimate training method: a smaller “student” model learns from a larger “teacher” model’s outputs. Anthropic calls it “illicit” when done covertly at industrial scale through fraudulent accounts — which it alleges here. Beijing’s position is that distillation is standard practice everywhere, including US companies.
What should NZ businesses do differently? Add model-provenance terms to AI procurement: which model answers, whether requests are ever forwarded to third parties, and where data lands. Assume the branded assistant is not necessarily the model that answered.
📰 Sources
- Anthropic — Detecting and countering misuse of AI: September 2026 (published 10 September 2026)
- WSJ — How Chinese AI Firms Tried to Clone U.S. AI Models (September 2026)
- CISA — joint cybersecurity advisory AA26-251A with FBI and NSA (8 September 2026)
- Yahoo Finance / Bloomberg — Moonshot Secretly Routed User Requests Through Claude (September 2026)
- BigGo Finance — Moonshot AI Accused of Illicitly Using Claude; PLA Surveillance Data Inadvertently Leaked to US AI (12 September 2026)
- Singularity.Kiwi — Anthropic Report Says Chinese Labs Routed User Chats to Claude Without Users Knowing
— CJ Murden, editor of Singularity.Kiwi. Former digital technologies teacher, author of AI-focused books. Writing with a New Zealand focus.