Anthropic Says Moonshot Sent 300,000 Requests to Claude Through 5,000 Accounts

The newly detailed episode puts Anthropic’s broader allegation in concrete terms: a rival AI lab allegedly used a large account network to access a model it could not commercially obtain in China.

By 3 min read
Anthropic Says Moonshot Sent 300,000 Requests to Claude Through 5,000 Accounts
Anthropic Says Moonshot Sent 300,000 Requests to Claude Through 5,000 Accounts

Listen to this story

The audio brief

About 1:30
0:001:30
Read transcript
Nearly 300,000 requests hit Anthropic’s Claude over just 10 days, routed through roughly 5,000 accounts and aimed mainly at Claude Opus. Anthropic says the traffic came from Moonshot AI and was part of an effort to extract capabilities for its Kimi models. One request reportedly asked Claude to analyze surveillance footage and judge whether someone was behaving abnormally. That concentrated episode sits inside a much larger allegation. In February, Anthropic said a broader Moonshot campaign generated more than 3.4 million exchanges through hundreds of fraudulent accounts, using both its API and third-party cloud platforms. Anthropic says the activity targeted capabilities including tool-using agents, coding, data analysis, computer-use development, computer vision, and Claude’s reasoning traces. The key dispute is not distillation itself. Using a stronger model’s outputs to train a smaller or cheaper one is a standard practice. Anthropic’s claim is that Moonshot allegedly gathered those outputs through unauthorized accounts and proxy routes designed to evade controls. Anthropic also says it does not offer commercial Claude access in China or to overseas subsidiaries of Chinese companies. In response, the company is tightening verification and developing behavioral fingerprinting and classifiers for coordinated, repetitive requests focused on narrow capabilities. The constraint to watch is whether providers can distinguish legitimate research from organized collection at this scale—without blocking ordinary high-volume users.

Story brief

3 key points

Anthropic is escalating its account of alleged model distillation by Moonshot AI, distinguishing authorized use of Claude outputs from access allegedly obtained through fraudulent accounts and proxy routes. The newly detailed 10-day episode involved nearly 300,000 requests across about 5,000 accounts, while an earlier disclosure attributed more than 3.4 million exchanges to a broader campaign. The dispute could...

  1. 01

    The concentrated episode mainly targeted Claude Opus and included a request to assess whether someone in surveillance footage was behaving abnormally.

  2. 02

    Anthropic says the broader campaign used hundreds of fraudulent accounts across multiple access pathways, including API and third-party cloud platforms.

  3. 03

    Capabilities allegedly targeted included agentic tool use, coding, data analysis, computer-use development, vision, and Claude reasoning traces.

Anthropic says Moonshot AI sent nearly 300,000 requests to Claude over 10 days through a network of about 5,000 accounts, primarily targeting the company’s Opus model. The newly detailed episode is part of Anthropic’s allegation that Moonshot used unauthorized access at scale to extract capabilities for its Kimi models.

A concentrated episode inside a larger allegation

Anthropic’s account of the 10-day period included a request to analyze surveillance footage for whether a subject was behaving abnormally. The company said the campaign mainly targeted Claude Opus. Those details emerged as Anthropic described several alleged large-scale attempts to harvest capabilities from its models.

The episode adds specificity to an earlier Anthropic disclosure. In February, the company said a Moonshot campaign associated with Kimi produced more than 3.4 million exchanges with Claude through hundreds of fraudulent accounts across multiple access pathways. Anthropic said it attributed that activity through request metadata matching public profiles of senior Moonshot staff.

The scale Anthropic described
Nearly 300,000Concentrated alleged episode

Anthropic said the requests passed through about 5,000 accounts and primarily targeted Claude Opus.

More than 3.4 millionBroader alleged Moonshot campaign

Anthropic said the wider campaign used hundreds of fraudulent accounts across multiple access pathways.

The dispute turns on access, not distillation alone

Distillation is a standard training practice: a developer can use a stronger model’s outputs to help train a smaller or cheaper system. Anthropic’s complaint is that Moonshot allegedly obtained those outputs through fraudulent accounts and routes designed to evade its controls, rather than authorized access.

Anthropic says it does not offer commercial Claude access in China or to overseas subsidiaries of Chinese companies. It says proxy services can operate large pools of accounts across its API and third-party cloud platforms, replacing accounts when they are blocked.

Capabilities Anthropic says were targeted

  • Agentic reasoning and tool use, which let a model plan work and call software tools.
  • Coding, data analysis, computer-use agent development and computer vision.
  • Claude reasoning traces, which Anthropic says Moonshot later tried to extract and reconstruct.

Anthropic’s next move is tighter detection

Anthropic says it has strengthened verification for educational accounts, security-research programs and startups. It is also developing classifiers and behavioral fingerprinting to identify coordinated activity and efforts to elicit hidden reasoning. The company treats unusually high-volume, repetitive requests aimed at a narrow capability as a key signal of suspected extraction.

For Moonshot, the claims remain Anthropic’s allegations, not an adjudicated finding. But the newly described traffic shows the practical boundary Anthropic is trying to defend: model providers must decide when unusual use is legitimate research and when it is coordinated collection of training material.

Editorial analysis

Our Read

The most consequential part of Anthropic’s allegation is not that one model learned from another. Distillation can be legitimate. It is the claimed combination of fraudulent accounts, proxy-based access and narrowly targeted requests for high-value capabilities. Anthropic’s case rests on behavioral patterns and metadata attribution rather than a single request, which makes its technical evidence central to the dispute. The next test is whether the company’s strengthened verification and traffic detection can curb suspected extraction without making legitimate model access much harder. The earlier U.S. advisory about alleged industrial-scale distillation gives the question wider policy weight, but it does not settle Anthropic’s allegation against Moonshot.

Sources

  1. anthropic.comDetecting and preventing distillation attacks
  2. techcrunch.comAnthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek | TechCrunch

Loading discussion...