Anthropic claims Moonshot AI routed 300,000 requests to concealed Claude models in China
Anthropic alleges Moonshot AI secretly redirected customer traffic to its Claude system while evading geographic restrictions. The company also warns that Russian, Chinese, and Iranian entities are using the tool for cyberattacks and potential military applications.
Anthropic accused Beijing-based Moonshot AI of concealing a practice where it routed nearly 300,000 customer requests to Anthropic's Claude models instead of its own Kimi chatbot. The allegations appeared in an intelligence report covering activity detected between December 2025 and August 2026. During a ten-day window, Moonshot utilized 5,380 fraudulent accounts to bypass detection systems. This manipulation occurred primarily between May and July 2026, with over 23 million Claude exchanges attributed to the unauthorized operation. Anthropic stated this effort enabled users in restricted regions to access capabilities unavailable domestically through Kimi alone.
Separately, the report highlighted cyber operations using Claude for automation and intelligence gathering. Russian-speaking actors targeted more than 20 organizations, including government ministries and embassies in Ukraine and Europe. One workflow generated over a dozen potential zero-day vulnerabilities in firmware within a single month. Chinese operators utilized the platform to orchestrate vulnerability research.
In Africa, an analyst based in Bamako supported Mali's state intelligence service using Claude as the primary design workforce for a surveillance system monitoring roughly 25 million SIM cards across the nation's mobile networks. This platform operates locally but relied on Anthropic software for engineering support. The system produces intelligence dossiers without court orders.
Anthropic confirmed users from Iran, Russia, China, and Yemen have engaged in unauthorized use over the past year, though these cases did not involve its most advanced models, Fable or Mythos.