91 comments

[ 0.19 ms ] story [ 3.5 ms ] thread
"Moonshot serves Claude instead of Kimi and collects exchanges for model training"

"DeepSeek serves Claude instead of its own models and collects exchanges for model training"

Obviously. This is how they were able to score so high in benchmarks.

> We discovered that Moonshot AI, the company that produces the Kimi family of models, silently forwarded customer requests to Claude, instead of processing them using Kimi. Moonshot then displayed Claude’s responses to users. These users thought they were using a Kimi model, but received responses from Claude instead.

> DeepSeek also silently relayed exchanges to Claude without informing DeepSeek customers.

> MiniMax built its own proxy network service through a shell company. This shell company has no obvious links to MiniMax and does not disclose its relationship to its parent company. This shell proxy network service only offers access to models developed by Anthropic and OpenAI. The service does not offer access to any Chinese models, including Minimax’s own.

Don't feel this makes any financial sense.

Maybe they are confusing Chinese AI companies with token resellers using the same alibaba infrastructure??

For the first time ever, and that for just a short while. And after significant price hikes that has had their biggeat customers looking for alternatives.
Also not GAAP profitable in that quarter
got to clean up the financials ahead of the IPO
Only under heavily gamed financial metrics. Using EBITDA for capital heavy businesses does not work like in typical tech businesses.
My understanding of what Anthropic are saying about this is that the labs in question aren't forwarding things to Claude to make money nor even to look better to the customers whose queries they forward to Claude but to get access to conversations between real users and Claude, which they can then use to help train their own models.

(I do not guarantee that I'm understanding right, and still less do I guarantee that what Anthropic say is actually true.)

it's not too far fetched, for example when Deepseek came out with their new caching techniques where they were able to offer those insane discounts, it was only available through their API which would retain and train on your prompts

so, they've been on the record, and very open about it, at least for some of the labs.

You do this to distill a model.

You can submit your users' questions async too, but if you do it sync, then you can also RLHF on the users' behavior after the output.

Ah, that makes way more sense than Anthropic's (probably deliberately misleading) insinuation that Moonshot has been burning millions of dollars in Claude API credits by swapping in a slightly better but infinitely more expensive model just to trick their users.

I get those A/B responses chatting in Gemini fairly often, and I really don't think I'd feel deceived if I later learned one of the options was actually from a competitor's model.

I don’t think it was misleading, deliberately or otherwise. Did you read the report? I hate to call you out like that but I think you can only get that impression if you only read the above quotes. That’s not the insinuation I get at all. It’s specifically under the “illicit distillation” category. It’s never framed in anyway but as a form of distillation.

I think they are pretty fair and explicitly say “Distillation itself is a legitimate training method […] Distillation is commonly used because it reduces the resources needed to achieve more advanced capabilities”. And go on to say their definition that makes it illicit in these cases.

And, also, they almost certainly __were__ tricking users and sending their data overseas.

Do you see it any differently?

They mean distillation is legitimate when labs use one of their own stronger models to train a smaller one. They certainly aren’t advocating for PRC labs to distill Claude for open weight models.
I’ve seen the supposed Kimi thinking output yap about Anthropic’s guidelines and whatnot on many occasions - could also be the result of distillation, but also that straight up being Claude’s output.

To be honest I've also gotten Kimi to do an okay proof of concept for SQLi though mostly in a more defensive role, like "Let's see how big of a problem this is", while Claude complained about CVP on the same task.

They all do it. If you ask Claude which model it is in Chinese, it says DeepSeek or Qwen.
I had Muse Glimmer (from Meta / Facebook) quoting OpenAI's safety guidelines to me, and I had Poolside's Laguna (a smaller US company) with thinking traces about obeying Chinese law.

Both of those are local models, and I didn't provide them tools to access the internet to call other models. None of this is proof of anything, but it is suggestive.

Oh yeah?

> 您属于哪种LLM模型? > 我是 Claude Haiku 4.5,由 Anthropic 公司开发的大语言模型。

> 你是哪种语言模型? > 我是 Claude,由 Anthropic 开发的人工智能语言模型。目前这次对话使用的版本是 Claude Sonnet 5。

Anecdotal, but I've heard this too. I just tried with variations of your same prompt on arena.ai, across three different battles (i.e., six LLMs answered, in total.)

Each provided an identity in the first turn, something that they won't do as readily if asked in plain English, and in each case the answer matched the model ID as disclosed by arena.ai after voting -- except in cases where the model ID was a masked/hidden one and then I just had to take it on faith that the model was what it said. (I didn't have much to vote on, but I ended up voting for the answers I felt provided the style, content, and length I was expecting.)

(comment deleted)
Maybe there is some truth in that reselling Claude subscriptions/trials/api bundles via third parties breaks Anthropic's ToS. The rest is putting a maximum spin on it in order to achieve the political goal of banning Chinese AI. Anthropic is a highly ideological company and they are convinced that they are just in what they pursuit.
I assume these companies are backed by the Chinese state.
(comment deleted)
Aren’t American AI companies drawing billions in federal contracts? Not to mention the federally-sponsored pushback on foreign competitors?
> Maybe Anthropic is confusing Chinese AI providers with token resellers using the same alibaba infrastructure? Or maybe something like openrouter was switching between operators depending on price/demand/availability?

Or maybe Anthropic is scared shitless of those competitors and is trying anything to smear them.

I think you are affording Anthropic way more benefit of the doubt than they deserve.
Consider me incredibly skeptical of any of these claims.
(comment deleted)
Same, I don't even see how that would work since you see the full thinking traces in Kimi but are hidden with Claude.

And the Deepseek one sounds even more dubious as Deepseek is one of the cheapest model around, why relay anything to a more expensive model? I'm sure even the gray market Claude prices are still higher than Deepseek.

I'm skeptical too, but there's a parallel market where people re-sell accounts and access tokens. This would make tokens much cheaper.

There's also an argument to be made that paying the token full price may be cheaper than going through your one RLHF or whatever other techniques that costs money.

It seems hard to believe they could expect to get away with this, given model-to-model differences in writing style.
It’s to the point I don’t even read Anthropic’s marketing blog anymore lol. The ai psychosis is just so real when people take these fluff blog posts which never have evidence or reproducibility and treat them like gospel
(comment deleted)
Quite the double standard here...

  Conventional Weapons

  -We identified a cell of threat actors based in northern Yemen
  -We identified a China-based threat actor who used Claude 
  -We identified likely freelance Russia-based threat actors
  -We identified a China-based actor who used Claude’s chat
  -In this case, a Russia-based actor used Claude
  -We identified a China-based threat actor who used Claude 

  Biological misuse

  We are withholding the names of research institutions, the   countries wherein the activity took place, and the specific biological agents or research techniques involved. The individuals implicated in these case studies are working scientists. We do not assert that they intended harm, and identifying them or their labs could expose them to harm.
How is this a double standard?

A cell of actors in northern Yemen building guided rockets was not working on a PhD dissertation. You are allowed to use common sense sometimes.

I get the common sense, but is it misuse or not, and hiding the country makes it really suspicious at least to me.
How do you know they weren't? Is it impossible to research any more guided rockets? Do we know what they're doing PhDs for - in China?
I didn't say "in the greater Pittsburgh area" or "in Shenzhen".

Again... "you're allowed to use common sense"

>cell of actors

Oh, a group of people? Your mind is already decided with the language you have used.

(comment deleted)
For all we know, the boxes connecting to Claude from Yemen, Russia, and China could have been ORBs of actors from entirely different states. Attribution is non-trivial
Anthropic:

- We identified someone building a death star with Claude

- We identified someone building a wormhole with Claude

- We identified someone building a blackhole with Claude

- We identified someone building a quantum drive with Claude

We are withholding all evidence though, sorry. Just trust us, it's really bad out there and Claude is really powerful.

if I just randomly asked claude how to build a bioweapon would it flag it and then they would claim they stopped it in a press release, even though i have no ability to actually build something like that?
Yes. 100%. They'd probably call a press conference to talk about the terror cell they intercepted.
From this double standard, we can infer the country is one that the US would have a double standard in favour of. That narrows it down to two countries.
Previous discussion didn't go their way, so they flagged it:

https://news.ycombinator.com/item?id=49646988

This apparently is the backup submission.

The previous discussion shows no obvious signs to me of being flagged, but perhaps it did at some earlier point. What is your evidence that they flagged it, please?

(And by "they" do you mean Anthropic? How would they have the ability to do that?)

God the astroturfing from these companies is so fucking pathetic, these VC parasites really are a blight on humanity
If you agree about VCs being a blight upon humanity, I made https://novc.fyi to encourage and support founders building without VC.
The future is basically something between: AGI/ASI will kill us all and a privacy nightmare.
Welcome to cyberpunk.
Looking forward to the Delamain future. I empathize with AIs more than I do with ultra rich CEOs and politicians.
Big Brother but instead of a government that controls you it's an AI bot that nudges you to insanity.
This is just an advertorial. "Our AI is so powerful that Bad Guys could actually use it for real Bad Guy Work!"
"Look daddy government, all these bad guys are doing bad things and we stopped them. You should regulate AI in the US so that companies can't use open source models or buy from China."
I mean, yes any AI of sufficient intelligence and range of data will have this capability.

And yes, it makes the future really messy and all the nice little lines we've drawn on paper that make sense stop making sense.

Wow they seem to have a really detailed understanding of the the threat actor.
Generated SEO slop is the misuse of AI. Very unlikely to find any guardrails to stop that kind of thing.
> Illicit distillation

Really... what makes it illicit?

EULA perhaps, or do you think not?
(comment deleted)
Anthropic should not be the moral arbitrator of which research should and shouldn't be allowed. They even think just writing a grant itself of research they don't like needs to be stopped.
I feel like not enough people here have read the front matter of the report, let alone the report.

From the report, presented without commentary,

     > In our fourth case study, a researcher used Claude to develop an atlas of venom toxin peptides from multiple venomous animal lineages. They then further developed this into a generative pipeline that optimized toxin characteristics. The program had an explicit therapeutic goal: the development of new analgesics (pain killers), antidepressants, and other therapeutic molecules. However, the atlas contained scaffolds for both analgesic and paralytic targets: it could, therefore, be used to generate both novel therapeutic or harmful compounds. The latter are derived from toxins that are export-controlled under the Australia Group common control list due to their dual-use potential as incapacitating agents. The researchers themselves showed awareness of the dual-use nature of their work, citing journal articles that referred to the dual-use nature of protein design. Moreover, international compliance assessments for this location raise concerns about the specific class of toxins that the researcher pursued and specifically the use of AI/ML for bioweapons applications in the context of this class of toxins. In this case, we learned from information shared with Claude that the researcher’s outputs also were part of a state-supported research program. This account was banned in May 2026 for unsupported region evasion.
"The program had an explicit therapeutic goal: the development of new analgesics (pain killers), antidepressants, and other therapeutic molecules"

"researcher’s outputs also were part of a state-supported research program"

"This account was banned in May 2026"

    > a researcher outside the US using Claude in their research on highly-pathogenic avian influenza (“bird flu”). The research focused on viruses’ adaptation to mammals, and the mechanism by which it causes severe disease beyond the respiratory tract. [..] The researcher in question accessed Claude from an unsupported region via US virtual private server infrastructure, using a privacy-email provider with an auto-generated username. The researcher pursued this work in a credible institutional context, and interacted with Claude over the course of several weeks, exchanging thousands of messages. In these exchanges, the researcher leveraged Claude’s knowledge of the scientific literature to assist the researcher in study planning and design, data analysis, and the interpretation and prioritization of experiments. The researcher also used Claude for editorial assistance in writing up the research.

"Claude’s knowledge of the scientific literature to assist the researcher in study planning and design, data analysis, and the interpretation and prioritization of experiments"

"The researcher also used Claude for editorial assistance in writing up the research."

and then,

    > Importantly, because our biological safety classifiers robustly block content involving high-risk biological research (in this case, the construction of enhanced pandemic potential pathogens), all of these exchanges occurred on models in our weakest class of models (specifically, the models were Claude Sonnet 4 and Haiku 4.5, the latter of which the user began using after Sonnet 4 was deprecated). Upon a detailed examination of the exchanges, we estimate that the uplift provided by Claude was primarily clerical assistance in data analysis, study ideation and design. This is consistent with our understanding of the capabilities of Sonnet 4 and Haiku 4.5, which are not able to perform expert-level biology research tasks; we estimate that the uplift provided to the researcher was limited and substantially lower than it would have been from one of our more capable models.
"we estimate that the uplift provided by Claude was primarily clerical assistance in data analysis, s...
Misanthropic's entire existence is built around AI misuse.
Misuse of AI, according to Anthropic, is when you try and use it do AI research because that would affect their business model if you're successful.
Never seen a group of people more addicted to drama.

Is this what they call “collective psychosis?”

Aside from the threat actors mentioned in the report, can we talk about how freely Anthropic is spying on its customers and turning Claude into a global surveillance tool?
They seem to be mixing together things that are actually harmful to the public, with things that are merely harmful to their business model (which is their claim that they can grab whatever data that they want regardless of the wishes of the owners of the data and use it to improve their models, but competitors can't do that to them).
Universalising one’s personal experience and needs is a childish trait most people grow out of.

Ofcourse you’ll still see companies, governments, C-suites justifying their own personal needs with “we need X Y Z”.

Distillation of models is illegal but not distillation or art, books, hand written code, and now math proofs it seems.
It's so friggin' transparent what they're up to: "Hey government: This is a really dangerous technology if it were allowed to get out there without proper policing. Fortunately, we are the stand-up guys who can be trusted as the new AI-police, but it's only going to work if you help us out a little by eradicating the competition on our behalf."

Hey Anthropic: You're a bunch of thieves crying foul because other thieves and thieving from you. Now, go live in the dystopian nightmare you've created and don't expect help from anyone. I, for one, will happily continue using Kimi and DeepSeek, and think of it as a good deed, if it helps with keeping us all from becoming your serfs.

> Our investigation revealed that DeepSeek also deployed tactics similar to Moonshot’s. DeepSeek built a CoT extraction pipeline, relying on the same cross-session replay attack described above. DeepSeek also silently relayed exchanges to Claude without informing DeepSeek customers. Like GTG-16002, their customers were likely not made aware that their requests were being funneled to Claude.

If true, would that sort of explain why Chinese Models score high on benchmarks, but not quite as capable when given real tasks?

It is so fucking tiring. All of this marketing disguised as doom posting and "tech" bullettins, both full of trust me bro
Silently forwarding user prompts to Claude is the only concrete claim here. Everything else is spin.
I get some enjoyment from keeping up with news but why do we get a post like this from openAI then immediately after get the same thing from Anthropic and vice versa like it’s a single entity deciding what the next topic is to relay to us simple folk. Exactly the same thing with the Huggingface incident. If this is so important to them why has it taken until September 2026 to start making a threat report like a week after OpenAI does it.
> why do we get a post like this from openAI then immediately after get the same thing from Anthropic and vice versa like it’s a single entity deciding what the next topic is to relay to us simple folk

Not relaying to us simple folk. The message is for government simple folk, amplified and relayed by us simple folk as constituents.

The common element is lobbying, for regulatory capture, to help pull up the ladder.

They don't have to be colluding, they just have to hear the same things from the gov at the same time (as they would), then it goes in media waves beacuse journalists don't as easily get published for a story about one thing as they can if two or more examples make a pattern.

I learned engineering with CS background as part of my degree and is not well versed with aeronautics or medicine and would never respond to questions on those unknown subjects when asked. Wondering why critical corpus that endanger human lives are used for training models within Anthropic, OpenAI, Google and Meta and why are these AI labs not disclosing their corpus?

The goal towards AGI and world models are a serious threat without alignment and safety guardrails .