Anthropic Says Moonshot Sent 300,000 Requests to Claude Through 5,000 Accounts
The newly detailed episode puts Anthropic’s broader allegation in concrete terms: a rival AI lab allegedly used a large account network to access a model it could not commercially obtain in China.
Listen to this story
The audio brief
Story brief
3 key pointsAnthropic is escalating its account of alleged model distillation by Moonshot AI, distinguishing authorized use of Claude outputs from access allegedly obtained through fraudulent accounts and proxy routes. The newly detailed 10-day episode involved nearly 300,000 requests across about 5,000 accounts, while an earlier disclosure attributed more than 3.4 million exchanges to a broader campaign. The dispute could...
- 01
The concentrated episode mainly targeted Claude Opus and included a request to assess whether someone in surveillance footage was behaving abnormally.
- 02
Anthropic says the broader campaign used hundreds of fraudulent accounts across multiple access pathways, including API and third-party cloud platforms.
- 03
Capabilities allegedly targeted included agentic tool use, coding, data analysis, computer-use development, vision, and Claude reasoning traces.
Anthropic says Moonshot AI sent nearly 300,000 requests to Claude over 10 days through a network of about 5,000 accounts, primarily targeting the company’s Opus model. The newly detailed episode is part of Anthropic’s allegation that Moonshot used unauthorized access at scale to extract capabilities for its Kimi models.
A concentrated episode inside a larger allegation
Anthropic’s account of the 10-day period included a request to analyze surveillance footage for whether a subject was behaving abnormally. The company said the campaign mainly targeted Claude Opus. Those details emerged as Anthropic described several alleged large-scale attempts to harvest capabilities from its models.
The episode adds specificity to an earlier Anthropic disclosure. In February, the company said a Moonshot campaign associated with Kimi produced more than 3.4 million exchanges with Claude through hundreds of fraudulent accounts across multiple access pathways. Anthropic said it attributed that activity through request metadata matching public profiles of senior Moonshot staff.
Anthropic said the requests passed through about 5,000 accounts and primarily targeted Claude Opus.
Anthropic said the wider campaign used hundreds of fraudulent accounts across multiple access pathways.
The dispute turns on access, not distillation alone
Distillation is a standard training practice: a developer can use a stronger model’s outputs to help train a smaller or cheaper system. Anthropic’s complaint is that Moonshot allegedly obtained those outputs through fraudulent accounts and routes designed to evade its controls, rather than authorized access.
Anthropic says it does not offer commercial Claude access in China or to overseas subsidiaries of Chinese companies. It says proxy services can operate large pools of accounts across its API and third-party cloud platforms, replacing accounts when they are blocked.
Capabilities Anthropic says were targeted
- Agentic reasoning and tool use, which let a model plan work and call software tools.
- Coding, data analysis, computer-use agent development and computer vision.
- Claude reasoning traces, which Anthropic says Moonshot later tried to extract and reconstruct.
Anthropic’s next move is tighter detection
Anthropic says it has strengthened verification for educational accounts, security-research programs and startups. It is also developing classifiers and behavioral fingerprinting to identify coordinated activity and efforts to elicit hidden reasoning. The company treats unusually high-volume, repetitive requests aimed at a narrow capability as a key signal of suspected extraction.
For Moonshot, the claims remain Anthropic’s allegations, not an adjudicated finding. But the newly described traffic shows the practical boundary Anthropic is trying to defend: model providers must decide when unusual use is legitimate research and when it is coordinated collection of training material.
Editorial analysis
Our Read
The most consequential part of Anthropic’s allegation is not that one model learned from another. Distillation can be legitimate. It is the claimed combination of fraudulent accounts, proxy-based access and narrowly targeted requests for high-value capabilities. Anthropic’s case rests on behavioral patterns and metadata attribution rather than a single request, which makes its technical evidence central to the dispute. The next test is whether the company’s strengthened verification and traffic detection can curb suspected extraction without making legitimate model access much harder. The earlier U.S. advisory about alleged industrial-scale distillation gives the question wider policy weight, but it does not settle Anthropic’s allegation against Moonshot.
Sources
- anthropic.comDetecting and preventing distillation attacks
- techcrunch.comAnthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek | TechCrunch
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.