Secret Proxy in Claude: Anthropic Accuses Kimi, DeepSeek and Alibaba of Stealing Reasoning and Swapping Answers

Anthropic has published a sweeping Threat Intelligence report for September 2026, leveling serious accusations against key players in China’s AI market. According to the American startup’s security team, the developers of the Kimi chatbot (Moonshot AI) and the DeepSeek lab secretly routed their own customers’ requests to a rival neural network, Claude, passing off the results as the work of their own algorithms.
The report also documents a large-scale industrial campaign of illegal “distillation” — training on a competitor’s outputs. In just three months, more than 151 million requests aimed at extracting hidden chains of reasoning from Claude models came from the infrastructure of IT giant Alibaba alone.
Kimi swapped its own answers for Claude Opus generations
Researchers found the boldest scheme in Kimi, the service from Chinese startup Moonshot AI. According to a post in Anthropic’s Threat Intelligence report, in a number of complex scenarios the company did not use its own neural networks at all.
Instead, a user’s request was intercepted on the backend and sent through a network of fake accounts to the flagship Claude Opus model. The generated answer was returned to the Kimi interface and shown to the customer as the company’s own achievement.
The scale of the substitution was considerable:
- During a single ten-day wave of checks, analysts identified a pool of 5,380 fake accounts (most disguised as Singaporean and Japanese IP addresses) through which about 300,000 customer requests passed;
- Total traffic linked to Moonshot’s servers from May through July exceeded 23 million conversational exchanges;
- Beyond serving answers directly to customers, the startup stored the generated conversations to train its own future models.
Anthropic classified the Chinese algorithm’s behavior as a mix of biased reasoning and a blind drive to close out a complex request at any cost: even when the Kimi model hit clear system markers showing the task was being handled in someone else’s environment, it kept proxying the conversation.
DeepSeek and the hacking of hidden thinking signature chains
Analysts recorded a similar shadow gateway in the DeepSeek lab’s infrastructure. According to the report, the system identified users who sent requests through professional development tools — Claude Code, OpenCode and the Claude Agent SDK — and then quietly redirected some complex engineering instructions to Claude Opus servers. As Reuters reports, in just two weeks in July specialists recorded more than 12.1 million such requests.
What interested the Chinese specialists was not just the final text but the intermediate “reasoning” the neural network produces before delivering an answer. To get around protective filters, the Asian developers used a replay attack on the thinking signature.
By passing a saved cryptographic reasoning marker into a new session, the attackers forced the model to reconstruct and dump into plain text the hidden internal decision-making steps that are normally blocked for outside users.
Leaks of state corporations’ confidential code
The use of secret proxying created unforeseen security risks for Chinese users themselves. Kimi and DeepSeek customers had no idea their confidential files were going to an American company’s servers.
Among the intercepted and proxied requests, Anthropic’s engineers found:
- Proprietary source code and active administrative access credentials belonging to a major Chinese state corporation;
- Internal surveillance footage that users uploaded to the chatbot for automatic incident recognition;
- Private financial and legal correspondence of commercial enterprises.
In effect, the Chinese services inadvertently leaked the PRC’s classified state and corporate secrets into the cloud infrastructure of their direct overseas competitor.
Alibaba’s record campaign: 151 million requests to train Qwen
The report calls the activity of the Alibaba holding the largest of all. Over three months of summer monitoring, researchers identified more than 151 million data-exchange sessions, with peak days reaching three million requests per day through a pool of more than 3,500 suspicious profiles.
Anthropic claims the cloud giant systematically scraped the logic of Claude Opus 4.6 and 4.7 to build training datasets. The collected data arrays were then used for supervised fine-tuning (SFT) and for configuring reinforcement learning (RL) environments in the creation of the open Qwen 3.5, 3.6 and 3.7 model line.
As Business Insider stresses, the published findings should be treated with healthy skepticism: the investigation was prepared by the commercial party to the conflict, which is competing for contracts with major corporate customers. Neither Alibaba, nor DeepSeek, nor Moonshot AI has offered public comment on the substance of the allegations.
Even so, the report exposed the hidden underside of the generative intelligence race: the loud successes and benchmark records of Asian models still rest largely on the covert exploitation of American flagships’ computing power and reasoning.