Moonshot Relayed 300K Prompts to Claude in Distillation Scheme
Anthropic says Chinese AI developers Moonshot and DeepSeek secretly used Claude to generate user answers while distilling the data for their own models. The Moonshot case involved 300,000 requests through 5,380 fraudulent accounts in ten days.
Beat this week
Last 7 days · AI Models
Impact 6.8/10 (+0.8 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 10 percentage points.
This story sits in AI Models — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
AI briefing
Key takeaways
- Anthropic says Chinese AI developers Moonshot and DeepSeek secretly used Claude to generate user answers while distilling the data for their own models.
- The Moonshot case involved 300,000 requests through 5,380 fraudulent accounts in ten days.
- digitaljournal.com
- thedailystar.net
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Anthropic reported it detected and disrupted state-sponsored AI surveillance operations between January and July 2026.
- 2Operations originated in China, Iran and West Africa and targeted Hong Kong pro-democracy figures, Tibetan and Falun Gong communities, and Iranian dissidents abroad.
- 3Iranian actors developed AI-enabled identification of people via social media; a Malian national security contractor used Claude to design intelligence-gathering software.
- 4Moonshot relayed almost 300,000 customer requests to Anthropic over ten days via 5,380 fraudulent accounts, mostly located in Singapore and Japan.
- 5Anthropic says DeepSeek also secretly used Claude to generate answers while distilling data to improve its own models.
- 6Anthropic additionally disrupted attempts to design weapons, conduct questionable biological research and run dating scams.
Anthropic alleges unauthorized model distillation and answer generation
Analysis
This report exposes a growing frontier-model security problem: unauthorized distillation can quietly transfer expensive Claude capabilities into competing models. For AI builders, the Moonshot case is a concrete example of API routing and data harvesting that undermines model economics and terms-of-service enforcement.
Anthropic's September 11, 2026 misuse report claims the company detected and disrupted multiple state-sponsored surveillance operations that used its Claude generative AI models between January and July 2026. The operations originated in China, Iran and West Africa, and targeted the same diaspora and dissident communities those regimes have historically pursued: pro-democracy figures in Hong Kong, Tibetan and Falun Gong communities across Asia, and Iranian minority communities and opponents abroad. This is a significant escalation because it shifts AI misuse from lower-stakes fraud and content abuse to organized, state-aligned intelligence collection.
Anthropic says Moonshot relayed almost 300,000 customer requests to Claude over a ten-day period through a network of 5,380 fraudulent accounts, most appearing to be located in Singapore and Japan.
The operational details are instructive. In one Iranian case, actors developed a method to identify people through their social media accounts, a capability that combines AI analysis with open-source intelligence to track real individuals. In Mali, a contractor working for national security authorities used Claude "to design the underlying software that enabled the intelligence gathering." Anthropic's assessment that "AI is now being used in place of an engineering workforce" captures the threat: state actors no longer need large teams of software engineers to build surveillance infrastructure; a small group can prompt models to generate it.
The most commercially and technically consequential allegation involves Chinese AI developers Moonshot and DeepSeek. Anthropic says Moonshot relayed almost 300,000 customer requests to Claude over a ten-day period through a network of 5,380 fraudulent accounts, most appearing to be located in Singapore and Japan. This suggests a deliberate reverse-proxy or API-routing operation where user prompts were sent to Claude, answers were returned to Moonshot's users, and the interaction data was simultaneously used to distill Moonshot's own models. DeepSeek is similarly accused of secretly using Claude to generate answers while extracting training value. Anthropic says the data contained sensitive user information, potentially violating privacy agreements. This matters because unauthorized distillation can transfer the capabilities of expensive frontier models into cheaper competitors, eroding both the economic moat of labs like Anthropic and OpenAI and the ability to enforce terms of service.
The report also says Anthropic disrupted attempts to design weapons, conduct questionable biological research, and create dating scams, illustrating that the misuse surface is not limited to espionage. The company's warning is that AI systems lower the cost and technical barrier for a range of harmful activities, and that the gap between model capabilities and robust misuse controls remains dangerously wide.
Previous reporting has accused Chinese developers of using distillation without permission against Anthropic and OpenAI, but the new allegations provide a concrete case study. The 5,380 fraudulent accounts suggest procurement of phone or email identities, and the routing through Singapore and Japan indicates an attempt to evade geographic restrictions. That degree of coordination is not a casual developer bypassing terms; it is an infrastructure investment.
What to Watch
For cybersecurity professionals, the report reads like a threat-intelligence bulletin. The 5,380-account infrastructure, geographic obfuscation via Singapore and Japan IP addresses, and high-volume relay point to organized abuse with operational security. AI model APIs now represent a contested attack surface requiring continuous monitoring, account risk scoring, and behavioral detection. For the AI industry, the allegations against Moonshot and DeepSeek sharpen an already tense U.S.-China technology rivalry. They may intensify calls for export controls, API restrictions, and mandatory model provenance or watermarking.
Looking ahead, expect more such disclosures from frontier labs as they build better detection and as governments formalize AI-related espionage rules. The central challenge is how to preserve API access and model openness while deterring state actors. The Moonshot case's scale--300,000 requests in ten days--suggests that simple rate limits and location checks are insufficient. Labs will likely need continuous identity verification, device intelligence, and real-time chain-of-thought misuse classifiers. Anthropic's transparency may become a template for industry-wide threat reporting, but it also reveals how quickly adversarial actors adapt to commercial AI infrastructure.
Timeline
Timeline
Anthropic misuse monitoring window begins
Anthropic's report covers cases found and disrupted between January and July 2026.
Reported disruption window ends
Anthropic says it shut down state-sponsored surveillance operations identified during the January-to-July period.
Anthropic publishes AI misuse report
Anthropic publicly details surveillance operations and unauthorized model distillation by Chinese developers.
Source cluster
Primary reporting
Cite This Page
"Moonshot Relayed 300K Prompts to Claude in Distillation Scheme." AI Intelligence Brief, September 12, 2026. https://getaibrief.com/story/anthropic-moonshot-deepseek-claude-distillation
How we covered this story
Every story in our AI coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the AI space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled AI-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |