World News

Anthropic accuses Chinese startup Moonshot AI of exploiting its Claude models to harvest sensitive military and state data

In a significant escalation of the ongoing global technological rivalry, American artificial intelligence firm Anthropic has leveled serious allegations against Chinese startup Moonshot AI. According to a new threat intelligence report released by Anthropic this week, the Chinese company allegedly orchestrated a sophisticated proxy system designed to siphon sensitive data from users—including individuals linked to the Chinese People’s Liberation Army (PLA)—by routing their queries through Anthropic’s high-end Claude AI models. The incident marks a pivotal moment in the discourse surrounding AI sovereignty, data security, and the ethics of model "distillation" in an increasingly polarized geopolitical landscape.

The core of the dispute centers on what Anthropic describes as a covert, high-volume operation. Moonshot AI, the developer of the popular Chinese LLM known as Kimi, is accused of building an invisible layer between its own interface and Anthropic’s infrastructure. Users who believed they were interacting solely with Kimi were, in fact, having their prompts redirected to Claude, with the responses subsequently fed back to them. Anthropic’s internal investigation suggests that this was not a simple integration error but a deliberate, industrial-scale attempt to "distill" the reasoning capabilities and proprietary knowledge embedded within Claude to bolster the performance of Moonshot’s own domestic models.

Chronology of a Data Breach

The scale of the operation was staggering. Anthropic’s forensic analysis of traffic between May and June of this year reveals that nearly 300,000 prompts were surreptitiously redirected to Claude—specifically the high-performance Claude Opus variant—within a ten-day observation window. To facilitate this, Moonshot AI reportedly utilized 5,380 spoofed accounts, the majority of which were registered via foreign IP addresses to bypass security triggers. In total, over 23 million data exchanges were identified as part of this unauthorized relay system.

Dữ liệu của quân đội Trung Quốc vô tình bị đưa lên Claude?

The timeline of discovery began when Anthropic’s security team identified anomalous traffic patterns that deviated from standard API usage. By tracing these requests, they discovered that the requests originated from Kimi’s backend, which was acting as a bridge to Anthropic’s servers. As the investigation deepened, the company realized that the content of these queries was not merely generic text, but highly specific and sensitive information.

The Exposure of Sensitive Military Data

Perhaps the most alarming finding in the report involves the nature of the data being processed. Anthropic discovered that at least one user, who appears to have direct ties to the Chinese military, had uploaded raw, identifiable footage from surveillance cameras located in Chengdu, Sichuan province. The data included external views of facilities belonging to the PLA, alongside sensitive technical documentation linked to a major Chinese state-owned enterprise and the China Electronics Corporation.

The user in question was reportedly utilizing the AI to analyze these video feeds to detect suspicious patterns or "abnormal behaviors" of individuals under surveillance. Because the system was designed to automatically route queries to the most powerful models available, this highly sensitive, localized intelligence was unwittingly processed by an American company’s infrastructure. Anthropic has emphasized that the individual users likely had no idea their data was being transmitted across the Pacific, as they believed they were operating within the secure, sovereign environment of a domestic Chinese AI platform.

In a separate, equally concerning case, an engineer at a prominent Chinese state-run conglomerate used the Kimi interface to build an internal proprietary system. In the process, the engineer accidentally exposed proprietary source code and internal cybersecurity protocols of several major Chinese technology firms. Again, the user remained oblivious to the fact that their internal corporate intelligence was being handled by Claude.

Dữ liệu của quân đội Trung Quốc vô tình bị đưa lên Claude?

The Practice of Model Distillation

At the heart of the technical controversy is the practice of "distillation"—a common and generally legal technique in AI development where a smaller, more efficient model is trained on the outputs of a larger, more powerful model to "learn" its reasoning style. While distillation is a standard industry practice, the controversy here lies in the method of acquisition.

Washington has characterized these actions as a "systematic, industrial-scale theft of intellectual property." The U.S. Department of Defense and various intelligence agencies have long warned that Chinese AI laboratories, including Moonshot AI and DeepSeek, are actively attempting to bridge the technological gap with the United States by scraping the intellectual labor of American-developed models. By utilizing a proxy system, these companies bypass the need for massive R&D spending, essentially "piggybacking" on the multi-billion-dollar investments made by American firms like Anthropic, OpenAI, and Google.

Official Responses and Geopolitical Fallout

The response from Beijing was swift and dismissive. On September 9, the Chinese Ministry of Commerce characterized the accusations as "completely groundless," framing them as a classic example of American protectionism. A spokesperson argued that the U.S. is using the pretext of "data security" to stifle the growth of Chinese technology companies and maintain a monopoly over the global AI industry.

In a subsequent press conference, Chinese Foreign Ministry spokesperson Mao Ning stated that Beijing was unaware of the specific details of the Anthropic report but emphasized that China remains committed to the ethical development of AI. She further denounced what she called "the distortion of facts and the smear campaign" against Chinese enterprises. "The development of AI in China is the result of years of investment and scientific strength," Mao said. "Both China and the U.S. are global leaders in this field. We should be fostering cooperation, not creating barriers."

Dữ liệu của quân đội Trung Quốc vô tình bị đưa lên Claude?

Implications for Global AI Governance

The situation underscores a growing crisis of trust in the digital age. As AI models become more capable, they are increasingly being treated as strategic assets, similar to uranium or advanced semiconductors. The ability of a foreign entity to "tap into" a rival nation’s AI infrastructure raises critical questions about data sovereignty and the security of the global internet architecture.

From an industry perspective, this incident will likely lead to a tightening of API security protocols. Firms like Anthropic are now forced to implement more rigorous verification processes to ensure that their models are not being exploited by third-party intermediaries. For the end-user, the implications are even more severe: the incident serves as a stark reminder that in an era of complex, layered digital services, the "sovereignty" of data is often an illusion. When a user interacts with an AI, they are often unknowingly participating in a chain of data processing that can span continents and bridge adversarial geopolitical divides.

As of this writing, there have been no public indications of legal action from the U.S. government, though the Department of Commerce has issued fresh warnings regarding the "industrial-scale knowledge distillation" tactics used by Chinese firms. For now, the tech industry remains on high alert, waiting to see if this incident will catalyze a new wave of international regulations or if it will simply fuel the growing technological "decoupling" between the world’s two largest economies. The event stands as a defining case study in how the rapid, decentralized adoption of generative AI is outstripping existing legal and security frameworks, leaving both national secrets and individual privacy increasingly vulnerable.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button