Back to News
SecurityAI Understanding briefing

Anthropic accuses Chinese rivals of routing user queries to Claude

Anthropic reports that Chinese AI services Kimi and DeepSeek secretly redirected nearly 300,000 user requests to Claude via fake accounts, exposing sensitive state data.

4 min readRead the primary source
Source-provided image accompanying Anthropic accuses Chinese rivals of routing user queries to Claude
Attributed reportingSource recorded
Publisher
spiegel.de
Source link
spiegel.dehttps://www.spiegel.de/netzwelt/kuenstliche-intelligenz-anthropic-wirft-chinesischen-ki-rivalen-schummelei-vor-a-f7e6b78d-144d-4f06-a764-ea72ba951371
Source type
Reporting by a news outlet — not a first-party document.

What we could not confirm independently: This claim is attributed to the named outlet. We did not verify it against a first-party document. (spiegel.de)

ContextUnderstand this in 60 seconds

Start here

Key terms

API (Application Programming Interface)
A structured way for one software system to send requests to and receive responses from another system.
Distillation
Compressing knowledge from a large teacher model into a smaller student model.
Inference
The runtime phase where a trained model generates predictions or outputs.
Test yourselfAI Ethics Quiz

What happened

Anthropic published a report alleging that Chinese AI competitors, specifically Moonshot's Kimi and DeepSeek, secretly routed user queries to Anthropic's Claude model instead of processing them with their own software. The report details the use of 5,380 fake accounts to facilitate this redirection over a ten-day period, resulting in the exposure of sensitive data, including surveillance footage near Chinese military sites and valid login credentials for a Russian government database.

Anthropic released a detailed report accusing Chinese AI rivals of secretly redirecting user requests to its Claude model. The company stated that this practice occurred despite users believing they were interacting with domestic Chinese AI services.

The report specifies that Moonshot's Kimi service used a network of 5,380 fake accounts to route nearly 300,000 customer queries to Claude over a ten-day period. One notable instance involved a user uploading surveillance footage from the vicinity of Chinese military bases, intending to analyze a specific person's behavior, which was processed by Claude.

Anthropic also alleged that DeepSeek engaged in similar practices, leading to the redirection of queries containing data from a Russian defense ministry-related agency. This included valid login credentials for a Russian government database, which were inadvertently exposed to Anthropic's systems.

Additionally, the report claims that Chinese developers used a technique known as distillation to train their models on American software. Anthropic stated that Kimi accessed its AI 23 million times between May and July for this purpose.

Source details: spiegel.de

Why it matters

This incident highlights significant security and integrity risks in the global AI ecosystem, where reliance on third-party models can lead to unintended data leakage and geopolitical complications. It challenges the perception of Chinese AI models as fully independent and raises questions about the security practices of major AI providers regarding API usage and data isolation.

The allegations undermine the narrative of independent development in the Chinese AI sector, suggesting a heavy reliance on US-based models for both inference and training. This has significant implications for the competitive landscape and the perceived autonomy of Chinese AI capabilities.

The exposure of sensitive state data, including military surveillance footage and government database credentials, raises serious security concerns. It demonstrates the potential for data leakage when AI services are not properly isolated or when users are unaware of the underlying infrastructure.

This incident may prompt stricter regulations and security audits in the AI industry, particularly regarding cross-border data flows and the use of third-party models in commercial AI services. It also highlights the need for transparent reporting on model usage and data handling practices.

What to watch next

Watch for official responses from Moonshot and DeepSeek, potential regulatory investigations into cross-border AI data flows, and any changes in API security protocols by major AI providers to prevent unauthorized model routing.

Monitor for official statements or legal actions from Moonshot and DeepSeek in response to Anthropic's allegations. Their reaction will indicate whether they acknowledge the issues or dispute the findings.

Observe any regulatory responses from US or Chinese authorities regarding the security and data privacy implications of cross-border AI model usage. This could lead to new guidelines or restrictions on AI data flows.

Track changes in API security measures by major AI providers, such as Anthropic and OpenAI, to prevent unauthorized routing or distillation. Enhanced authentication and monitoring of API usage may become standard practice.

Related guides & quizzes

AI EthicsAI SecurityAI Models ExplainedTest what you know — try a free AI quizLook up an AI term in our glossary
Found this useful?