# Anthropic Says DeepSeek and Moonshot Routed Customer Prompts to Claude Through Fake Accounts

The company reports 5,380 fraudulent Moonshot-linked accounts that relayed roughly 300,000 requests in ten days, and more than 12 million distillation attempts it attributes to DeepSeek over 14 days in July.

- Published: 2026-09-12T06:23:24.914Z
- Canonical: https://polylog.news/ai/2026-09-12/anthropic-says-deepseek-and-moonshot-routed-customer-prompts
- Publisher: Polylog (AI desk)
- Section: tech
- Sources: [Anthropic](https://www.anthropic.com/threat-intelligence-report-september-2026), [Polylog editors](https://polylog.news), [CNBC](https://www.cnbc.com/2026/09/11/chinese-ai-labs-moonshot-deepseek-alibaba-anthropic.html), [South China Morning Post](https://www.scmp.com/news/us/diplomacy/article/3367112/moonshot-deepseek-secretly-routed-user-requests-claude-anthropic-claims)

Anthropic's [September threat intelligence report](https://www.anthropic.com/threat-intelligence-report-september-2026) makes an accusation that goes beyond ordinary model distillation. The company says Moonshot AI and DeepSeek did not merely train on Claude's outputs. According to Anthropic, the two companies relayed live customer prompts to Claude and returned Claude's answers to users who believed they were talking to a Chinese model.

The figures Anthropic reports are specific. It attributes 5,380 fraudulent accounts to Moonshot, most of them presenting as based in Singapore and Japan to work around geographic restrictions, and says close to 300,000 customer requests were relayed over a single ten-day window, with most of that traffic sent to Opus. For DeepSeek, Anthropic says it observed more than 12 million distillation attempts over 14 days in July 2026. It also names operators affiliated with Alibaba as using Claude's outputs to help train Qwen models, [according to CNBC's account](https://www.cnbc.com/2026/09/11/chinese-ai-labs-moonshot-deepseek-alibaba-anthropic.html).

The most consequential part of the report concerns data rather than model weights. If prompts were relayed as described, then whatever users typed reached Anthropic's servers. Anthropic says some of those exchanges contained sensitive material from individuals, multinational companies, and state-affiliated actors, including live credentials for a Russian government database and a query from a user it links to China's military about behavior tracked across surveillance cameras in Chengdu. The [South China Morning Post](https://www.scmp.com/news/us/diplomacy/article/3367112/moonshot-deepseek-secretly-routed-user-requests-claude-anthropic-claims) reported the allegations as claims made by Anthropic, not as established fact.

Readers should weigh the evidentiary gap here. The account rests entirely on Anthropic's internal account telemetry and abuse investigation, which no outside party can inspect, and Anthropic is a direct commercial competitor of every lab it names. The accused labs have not published a detailed technical rebuttal. The claim is detailed and internally consistent. It is also unverified by anyone outside the company.

## What this means

For anyone building on a Chinese API, the exposure is contractual and legal, not technical. If a provider silently subcontracts inference to a United States vendor, the prompt data crosses a border the customer never agreed to, which breaks data-residency commitments and, for regulated sectors, breaks compliance requirements. Anthropic gains leverage to tighten identity verification and regional access controls on its own API, which also raises the cost of anonymous bulk access for every legitimate developer. Either the accused labs produce evidence contradicting the traffic analysis, in which case this reads as competitive positioning, or they do not, in which case enterprise buyers in Europe and Asia will start demanding auditable proof of which model actually served a request.

## What to watch

- Whether DeepSeek, Moonshot, or Alibaba publish a technical response, since silence and a detailed rebuttal point to very different underlying facts.
- Whether API vendors begin offering cryptographic or audited proof of which model served a given request, which would turn provenance into a product feature rather than a promise.
- Whether regulators in jurisdictions with data-residency rules open inquiries into prompt routing, which would move this from a company dispute into a legal enforcement matter.
