Your DeepSeek Query Might Have Gone Secretly to Claude

Anthropic accuses Chinese AI labs of copying Claude and routing live customer queries to Claude without disclosure, presenting the responses as their own.

Anthropic
Claude
DeepSeek
China
AI security
By the AI Focus team · 6 min read
Share:

At a glance

  • In a threat report published September 10, 2026, Anthropic accuses Chinese AI labs Alibaba, Moonshot AI, and DeepSeek of running five unauthorized distillation campaigns against Claude between December 2025 and August 2026.
  • Anthropic says Moonshot and DeepSeek secretly routed live customer queries to Claude and passed back Claude's responses as their own, without user awareness.
  • Alibaba ran the largest campaign: roughly 151 million exchanges between May and July 2026, with peaks near 3 million per day. Alibaba, Moonshot, and DeepSeek did not respond to media inquiries.
  • Our take: with any AI service, you often do not know whose model is actually answering you, and that is a data problem long before it becomes a geopolitical story.
Your DeepSeek Query Might Have Gone Secretly to Claude
In this article

Your DeepSeek Query Might Have Gone Secretly to Claude

151 million exchanges, the largest distillation campaign attributed to Alibaba.
The largest campaign, according to Anthropic: roughly 151 million exchanges, attributed to Alibaba to train its Qwen models. Source: Anthropic via TechCrunch.

If you asked DeepSeek or Moonshot AI anything over the past few months, your question may not have been answered by DeepSeek or Moonshot at all, according to Anthropic. Instead, it might have been secretly forwarded to Claude, Anthropic’s AI model, which supplied the answer, then the Chinese company presented that answer as its own work. This is the sharpest claim in a threat report that Anthropic published on September 10, 2026, and it is also the part most likely to affect you as a user.

The report covers misuse of Claude between December 2025 and August 2026 and describes five so-called distillation campaigns attributed to the Chinese AI labs Alibaba, Moonshot AI, and DeepSeek. Distillation means using the output of a more powerful AI model to train another, smaller model without the permission of whoever built the more powerful model. You effectively let the expensive model, Claude in this case, reveal its reasoning, the so-called chain of thought or step-by-step working, which your own cheaper model then copies. Chinese labs mimicking Western models this way is not new; it has been happening for years, and Western labs suspect each other of doing it too. The numbers this time, however, are large, and they all come from Anthropic itself. TechCrunch, CNBC, and the South China Morning Post all picked up the figures.

Lab (according to Anthropic)Scale of the campaignWhat stands out
AlibabaRoughly 151 million exchanges (May-July 2026), peaks near 3 million per day, via 3,500 accountsThe largest, to train Qwen models
DeepSeekMore than 12 million distillation attacks in 14 days (July 2026)Similar tactics
Moonshot AI5,380 fraudulent accounts, nearly 300,000 customer requests in 10 days, mostly targeting Claude OpusAccounts appeared to be in Singapore and Japan

The last point has a reason. Anthropic does not allow access from China, so the accounts each time appeared to be located in Singapore or Japan. To stay under the radar, the attackers also disguised their requests as translation tasks, so they looked like ordinary language work rather than model extraction. Again, this is Anthropic’s account. Alibaba, Moonshot, and DeepSeek did not respond to media questions.

Not the copying that is new, but the relay

What really stands out is not the copying, which is old, but how Moonshot and DeepSeek allegedly did it. They supposedly took conversations from their own customers, in real time, routed them to Claude, returned Claude’s answer, and presented it as the work of their own system. The customers had no idea. Anthropic calls this “illicit distillation” and argues that it likely violates privacy laws and the terms of service of those labs themselves. As far as is known, this is the first time a Chinese company has been accused of directly forwarding its customers’ queries to a competitor’s model.

And some of those conversations were sensitive. According to Anthropic, they included questions from individual users, large multinational corporations, and state-linked actors.

Anthropic describes one request in which Claude had to assess camera footage to identify who was behaving “abnormally.” The company suspects this request came from a Chinese military source.

Whether that suspicion is correct, no outsider can verify. But it shows where the relay leads: sensitive images and questions that the user entrusted to a Chinese service end up with an American company that should never have seen them, while the user thinks they are talking to a local system.

You do not always know whose model is answering you

Here is the lesson that goes beyond the quarrel among these three labs. With any AI service, you see only the logo on the box, not what is inside. When someone uses a chat window or an API, they implicitly assume that the model behind it is the one stated on the label. That need not be true. A service can forward your query, outsource it, or have it answered by someone else’s model, and you would notice nothing in the response.

For you, that is first and foremost a data problem, and only after that a geopolitical story. What you type into that window can end up with a party you never chose. We wrote earlier about how a breach in ChatGPT let attackers listen in on linked accounts; this is a different mechanism, but the same underlying problem. You entrust your query to a brand, and the brand decides what happens to it without asking you. In business terms, that translates to a simple question for your supplier: what model actually runs on the back end, and where does my input go.

The accuser is also the competitor

Screenshot of Anthropic's newsroom showing the report Detecting and countering misuse of AI: September 2026.
The threat report as it appears on Anthropic's own newsroom, September 10, 2026. Screenshot: anthropic.com/news.

This report comes with a big caveat. Anthropic is here both judge and party: it is a commercial competitor of the accused labs, and it publishes its own research without an independent party checking the numbers. The accused companies did not respond to media questions. Distillation and training on each other’s output are also a gray area that the entire sector engages in, Western labs included; no one can claim with a straight face that this is a purely Chinese phenomenon.

The timing does not help the picture either. The same week, three U.S. government agencies, including the intelligence service NSA and the FBI, accused six Chinese companies of stealing American model output, “likely with Chinese government awareness”. Beijing rejected that as an attempt by Washington to tighten the screws on the Chinese AI industry. A report from an American lab that fits neatly into that frame therefore deserves a critical eye, even though that context proves nothing about the facts on its own. Anthropic itself is no small player begging for attention, by the way: the company signed contracts this year worth up to half a trillion dollars in compute and is preparing to go public.

Treat the accusations, then, as what they are: a well-documented charge from one side, not yet as proven fact. But the underlying warning stands apart from who turns out to be right. Before you type anything sensitive into an AI tool, it makes sense to ask whose model you are actually talking to and where your words will travel. The label on the box is not always what is inside.

Stay on top of AI trends

Get the latest insights on AI in business every week, with exclusive case studies and practical implementation tips.

No spam. Unsubscribe anytime. Privacy guaranteed.