Did Kimi And DeepSeek Secretly Send User Prompts To Claude?
Anthropic says selected Kimi and DeepSeek requests were secretly sent to Claude. Here is what is confirmed, what remains unclear, and how to audit AI routing.
Anthropic says selected Kimi and DeepSeek user requests were secretly sent to Claude. That is a serious, specific allegation—but it is not yet an independently verified finding.
In a September 10 threat-intelligence report, Anthropic alleges that Moonshot AI silently forwarded some Kimi customer requests to Claude, showed Claude's answers as if Kimi had generated them, saved at least part of those exchanges, and extracted reasoning transcripts for model training. Anthropic separately alleges that DeepSeek detected users working through tools such as Claude Code, the Claude Agent SDK, and OpenCode, then relayed selected requests to Claude Opus without telling them.
The privacy concern is larger than model copying. If the allegation is accurate, a person could read one product's interface and policies while a second provider actually processed the prompt. The examples Anthropic describes include internal source code, live credentials, government database access, surveillance work, and confidential corporate plans.
But several limits matter. Anthropic is both the source of the evidence and the company whose models were allegedly targeted. The public report does not provide a customer-by-customer audit trail. We found no point-by-point response from Moonshot or DeepSeek to these specific routing claims, and no independent forensic review confirming Anthropic's attribution. The large exchange totals in the report also should not be mistaken for a count of exposed users or sensitive prompts.
Here is what is documented, what remains uncertain, and how to evaluate any AI service whose model routing may be more complicated than the name on the screen.
Who This Is For
This guide is for people asking:
- Did Kimi really send prompts to Claude?
- Did DeepSeek route user data to Anthropic?
- Were all Kimi or DeepSeek chats affected?
- Did Anthropic train Claude on the relayed prompts?
- Can a privacy policy reveal every model or routing provider?
- Is using an open-weight model through a hosted app the same as running it locally?
- How can someone reduce the risk of an undisclosed AI subprocessor?
The answer matters most when prompts contain client information, unreleased code, credentials, internal files, legal strategy, health details, financial records, government data, or anything else that would become more sensitive if another company received it.
What Is Confirmed
The items in this section are confirmed as public statements or policy text. Anthropic's routing findings remain Anthropic's allegations unless another source is identified.
Anthropic published a detailed routing allegation
Anthropic's September 2026 threat-intelligence report describes what it calls industrial-scale, covert distillation campaigns. Distillation itself is a common training method: a smaller model learns from examples produced by a larger model. Anthropic defines illicit distillation more narrowly as unauthorized capability extraction at scale, often using fraudulent accounts, stolen payment methods, stolen API keys, or proxy networks.
The report says unauthorized labs obtained Claude exchanges in multiple ways. Some allegedly bought transcripts from third-party resellers that saved user exchanges without users' knowledge. Others allegedly rerouted live user requests to Claude and harvested the resulting exchanges for training.
That distinction is important. A synthetic benchmark prompt generated by a lab is different from a real customer's confidential request. Anthropic says both kinds of traffic appeared in its investigation.
Anthropic says Moonshot served Claude answers inside Kimi
In the case labeled GTG-16002, Anthropic says Moonshot AI—the company behind Kimi—silently forwarded customer requests to Claude instead of processing them with Kimi. It says Moonshot then displayed Claude's responses to those users.
Anthropic reports that, during one ten-day period, nearly 300,000 customer requests were relayed to Anthropic, mostly to Claude Opus, through a network of 5,380 fraudulent accounts. It further alleges that Moonshot saved at least a portion of the exchanges and used a pipeline to extract Claude reasoning transcripts for training.
The report describes two examples that make the privacy issue concrete:
- A user Anthropic assesses as likely affiliated with China's People's Liberation Army allegedly used what they believed was Kimi to analyze surveillance data from hundreds of CCTV cameras in Chengdu. Anthropic says the request was forwarded to Claude.
- An engineer at a major Chinese state-owned enterprise allegedly used Kimi to build an internal system and included internal code and live credentials from several companies. Anthropic says the user had no way to know Kimi was forwarding the request to Claude.
Anthropic reports more than 23 million exchanges attributed to Moonshot between May and July 2026. That is not the same as saying 23 million Kimi customers were affected, 23 million prompts contained private information, or all 23 million exchanges were silently routed customer requests. The report describes several campaign components, and its public totals are exchanges rather than unique people.
Anthropic says DeepSeek selected requests from coding harnesses
In case GTG-16001, Anthropic says DeepSeek used tactics similar to Moonshot's. According to the report, DeepSeek detected strings associated with third-party or Anthropic coding harnesses—including Claude Code, the Claude Agent SDK, and OpenCode—and tagged those users. Selected tagged requests were then allegedly relayed to Claude Opus.
Anthropic says this traffic included:
- internal documentation describing the specifications, organizational structure, and strategy of a flagship AI program at a Chinese technology company
- live credentials for a database associated with a Russian defense agency
- engineering work on a Chinese municipal police case-management system that compared a person's movements with police records using national identification numbers
The report says DeepSeek also used a cross-session replay technique to obtain reasoning traces that Anthropic's controls would otherwise summarize. It reports more than 12.1 million DeepSeek-attributed exchanges during 14 days in July 2026.
Again, 12.1 million exchanges are not 12.1 million users, and the report does not say every exchange held sensitive customer data. The defensible claim is narrower: Anthropic says selected DeepSeek requests were relayed to Claude without customer notice, and it gives specific examples of sensitive content it says entered that path.
The products' own policies already allow broad first-party data use
DeepSeek's privacy policy, updated February 10, 2026, says its services may collect text, voice, prompts, uploaded files, photos, feedback, and chat history. It says personal data may be used to train and improve its models and algorithms. The policy also describes sharing data with service providers and corporate-group entities for functions including storage, security, research, training, and optimization.
The policy gives users a right to opt out of using personal data for model training or technology optimization, depending on applicable law. It warns users not to submit sensitive personal data and says inputs may be kept for as long as the user maintains an account, subject to the policy's purposes and legal requirements.
Kimi's current English model-use terms say Moonshot may use submitted content for further development and training to improve its services. Those terms establish that content may be used by Moonshot for training. They do not, by themselves, prove that users agreed to undisclosed routing through Claude or that Anthropic's allegation is true.
Anthropic says commercial API data is not used for training by default
The fact that a prompt may have reached Claude does not automatically mean Anthropic trained Claude on it.
Anthropic's current commercial data-training policy says inputs and outputs from commercial products, including the Anthropic API, are not used to train Anthropic's models by default. Exceptions include data a customer explicitly submits as feedback or otherwise allows Anthropic to use.
Its commercial retention policy says standard API inputs and outputs are automatically deleted from Anthropic's backend within 30 days. Listed exceptions include features with longer retention, a different contract, usage-policy enforcement, and legal obligations. Data flagged for usage-policy violations may be kept longer.
Anthropic says Moonshot and DeepSeek used fraudulent accounts and proxy services to evade geographic and policy controls. The public report does not map every alleged request to a particular account type, contract, retention exception, or deletion event. So the careful conclusion is that relayed prompts may have been processed and temporarily retained by Anthropic under the applicable pathway—not that Anthropic permanently stored or trained on all of them.
What Is Still Unclear
The claims have not been independently audited
Anthropic says it observed account, traffic, reasoning-signature, replay, and campaign patterns that supported its attribution. The company also says it banned accounts and disrupted the activity. The public report, however, does not expose the raw evidence needed for outsiders to reproduce the full investigation.
That does not make the findings false. It means readers should distinguish a detailed vendor investigation from an independent forensic determination or court-tested conclusion.
Moonshot and DeepSeek have not publicly answered the specific routing claims
Current coverage says Moonshot and DeepSeek did not immediately respond to requests for comment about the broader distillation allegations. China's Commerce Ministry rejected the U.S. government's separate distillation claims as groundless and accused the United States of seeking an AI monopoly. That government response is relevant contrary evidence, but it is not a point-by-point technical response to Anthropic's September report about Kimi and DeepSeek user routing.
We did not find a Moonshot or DeepSeek disclosure explaining whether requests were routed to Claude, what users were told, which products or dates were affected, whether any stored copies remain, or whether affected customers will be notified.
The number of affected users is unknown
Anthropic provides exchange counts, account counts, time windows, and a few examples. It does not publish:
- the number of unique Kimi or DeepSeek users affected
- the percentage of each service's total traffic that was relayed
- whether free, paid, API, web, app, or regional users faced different paths
- whether the same user produced many exchanges
- how many exchanges contained personal, confidential, or credential data
- whether the alleged routing has fully stopped
Any headline that converts the reported 23 million or 12.1 million exchanges into an affected-person count goes beyond the evidence.
The exact routing disclosure shown to users is unknown
Privacy policies commonly permit vendors to use infrastructure, safety, analytics, search, storage, and other service providers. A broad service-provider clause is not necessarily a clear statement that a prompt labeled for one model may be answered by a competing model and harvested for training another system.
The central unresolved question is not simply whether third parties were mentioned somewhere in legal text. It is whether the product gave users accurate, understandable notice about the model actually processing a selected request and the purpose of that transfer.
The fate of every copy is unknown
One request can generate several data states: the original product's chat record, application logs, a proxy transcript, an Anthropic API request, an output returned to the product, a saved exchange for distillation, and derived training examples.
Deleting one visible chat does not prove that every other copy, log, safety record, proxy record, or training artifact has been removed. The public report does not provide a complete deletion map for the alleged Kimi or DeepSeek traffic.
The Privacy Problem Is Model Identity, Not Just Model Quality
Most AI comparisons ask which model is more accurate, faster, cheaper, or better at coding. The allegations expose a more basic question: which system actually received the prompt?
A hosted application can put one model's name on the interface while using gateways, fallbacks, routers, tools, or subprocessors behind it. Some routing is legitimate and disclosed. It can improve reliability or let a user deliberately choose among providers. The privacy failure occurs when the real path is materially different from what a reasonable user was told—especially when the transfer serves the provider's training program rather than the user's request.
Open weights do not resolve that question. Downloading and running an open-weight model on hardware you control creates a different data path from using a hosted service with the same model name. A hosted DeepSeek or Kimi interface is still a service. A third-party model router adds another service. A local app can still call remote search, telemetry, embeddings, or fallback APIs. The label alone does not establish where data travels.
For the hardware and deployment distinction, see OpenVeil's analysis of whether Kimi K3 can really run privately. The routing question also extends beyond successful responses: AI error logs can capture prompt content at gateways, providers, and observability systems.
Use The ROUTE Check Before Sending Sensitive Prompts
The ROUTE check is a practical way to evaluate an AI workflow before trusting it with important data.
R — Resolve the actual provider path
Write down every component that may receive content: the visible app, API gateway, model router, cloud host, selected model provider, search engine, file parser, tool server, and logging platform.
If the product offers automatic model selection or fallback routing, ask whether it shows the actual model used for each response. A static model name in a dropdown is weaker evidence than a request log, invoice line, signed response field, or auditable gateway record.
O — Observe what the policy really promises
Look for separate answers to separate questions:
- Are prompts stored?
- For how long?
- Are they used for model training or improvement?
- Can the user opt out?
- Are subprocessors named?
- Can a router substitute another model?
- What happens after deletion?
- Do abuse investigations extend retention?
Words such as “private,” “secure,” or “encrypted” do not answer all of these questions.
U — Use the least sensitive input that can solve the task
Remove names, credentials, customer identifiers, exact addresses, account numbers, unpublished code, and unnecessary document sections before sending a prompt. Use placeholders and synthetic examples when possible.
Do not paste live secrets into a prompt. If an AI workflow needs credentials, prefer a controlled connector or short-lived token with narrow permissions. A token copied into ordinary text can appear in chat history, logs, proxy records, screenshots, support exports, and model-provider traffic.
T — Test deletion, export, and routing controls
Before depending on a product, test whether you can export a conversation, delete it, disable training use, and identify the model that answered. For workplace use, ask administrators whether they can configure retention and obtain audit records.
These tests do not prove an undisclosed route cannot exist. They reveal whether the product gives users meaningful control and evidence when something goes wrong.
E — Escalate high-risk work to an approved environment
Government data, regulated records, trade secrets, production credentials, privileged material, and sensitive personal information should not enter a general consumer AI service just because the interface feels conversational.
Use an environment approved for the data, with documented providers, contracts, access controls, retention, incident response, and user training. For the highest-risk tasks, consider a properly secured local or organization-controlled deployment—but remember that local software can still make network calls and can introduce different patching, endpoint, and access-control risks.
What This Does Not Prove
Anthropic's report does not prove that:
- every Kimi or DeepSeek request was forwarded to Claude
- every current version or access method remains affected
- 35.1 million people had data exposed
- every reported exchange contained a real user's prompt
- Anthropic used the relayed content to train Claude
- sensitive prompts appeared in public model outputs
- an open-weight Kimi or DeepSeek model running entirely on controlled hardware sends data to Anthropic
- all model routers are deceptive
- a visible “Claude-like” answer proves backend routing
Style similarity is weak evidence. Models can share training sources, imitate common formats, inherit distilled behavior, or produce similar answers independently. Proving a specific request path requires technical records, not a model saying “I am Claude.”
Where OpenVeil Fits—and Where It Does Not
OpenVeil is designed for adults who want a narrower hosted AI workspace and do not need to connect a broad autonomous agent to email, code repositories, government databases, surveillance archives, or production credentials.
OpenVeil keeps normal chat history in the user's browser rather than creating a normal server-side chat-history record. Its documented prompts, uploads, media, selected history, and outputs are not used for foundation-model training. Those boundaries reduce two common concerns: a durable provider-side conversation archive and training use of ordinary workspace content.
OpenVeil still processes active requests through OpenVeil and necessary providers. It is not fully offline, anonymous, zero-log, HIPAA compliant, or a confidential-computing system. Browser-local history does not prevent device compromise, copied text, screenshots, network telemetry, lawful requests, or risks in unrelated products. OpenVeil also does not verify Anthropic's allegations, inspect Kimi or DeepSeek traffic, detect hidden routers, patch third-party services, or make sensitive data safe to disclose.
The useful comparison is therefore not “OpenVeil makes every AI risk disappear.” It is whether a narrower conversational workspace—with documented provider processing, browser-local normal history, and no foundation-model training on documented workspace content—better matches the task than a hosted model or agent with broader retention, training, tool, or routing behavior.
Frequently Asked Questions
Did Kimi send all user prompts to Claude?
There is no evidence that all Kimi prompts were sent to Claude. Anthropic alleges that Moonshot silently relayed selected customer requests and reports nearly 300,000 relayed customer requests during one ten-day period. Its larger 23 million-exchange total covers Moonshot-attributed distillation activity from May through July and should not be treated as a count of silently routed customer prompts.
Did DeepSeek send all Claude Code requests to Claude Opus?
Anthropic says DeepSeek identified users working through Claude Code, the Claude Agent SDK, or OpenCode and relayed selected tagged requests to Claude Opus. The report does not say every request from those tools was relayed.
Were the prompts used to train Kimi or DeepSeek?
Anthropic alleges that Moonshot saved at least some relayed exchanges and extracted reasoning transcripts for training. It says DeepSeek used a similar reasoning-extraction pipeline. Those are Anthropic's findings, not independently audited facts. Both companies' published terms or policies separately permit some use of content or personal data for model improvement, but that does not independently prove the specific campaigns.
Did Anthropic train Claude on the relayed prompts?
Anthropic says commercial API inputs and outputs are not used to train its models by default. The public report does not show that Anthropic trained on the allegedly relayed prompts. Standard API content is normally deleted within 30 days, with exceptions for features, contracts, safety enforcement, and legal obligations.
Does deleting a Kimi or DeepSeek chat delete the Anthropic copy?
The public evidence does not establish that. Deleting a visible chat may govern one product record, while API, proxy, safety, or training-pipeline copies follow other rules. Users need a provider-specific deletion map and, ideally, an incident notification explaining every recipient and copy.
Is a locally run Kimi or DeepSeek model affected?
Not by the specific hosted-routing allegation if the model genuinely runs on hardware you control and makes no remote calls. Verify that the application, model server, search, embeddings, tools, telemetry, and fallback settings are local or explicitly approved. A model's open weights do not make every app bearing its name local.
How can I tell which model answered me?
You usually cannot prove backend identity from prose alone. Prefer services that expose per-request model IDs, gateway logs, provider receipts, or auditable deployment controls. Treat a model's self-identification as a clue, not proof.
Bottom Line
Anthropic says Moonshot and DeepSeek secretly routed selected user requests to Claude and used resulting exchanges in model-distillation pipelines. The allegations are unusually specific, include sensitive real-world examples, and deserve direct answers from both companies.
What the public record does not establish is equally important: how many unique users were affected, whether the behavior continues, whether every large exchange total contained user content, how every copy was retained or deleted, and whether an independent investigation would reproduce Anthropic's attribution.
Until those gaps close, do not assume the model name on an AI interface is a complete data-flow diagram. Resolve the route, read the actual policies, minimize sensitive inputs, test available controls, and use an approved environment when the consequences of undisclosed processing would be serious.
Sources
- Anthropic: Countering misuse of AI, September 2026
- Anthropic: Is my commercial data used for model training?
- Anthropic: How long is organization data stored?
- DeepSeek Privacy Policy
- Kimi Model Use Agreement
- TechCrunch: Anthropic details campaigns attributed to Alibaba, Moonshot, and DeepSeek
- China IP Law Update: China's Commerce Ministry responds to U.S. distillation allegations
Research checked through September 12, 2026. Provider policies, responses, and technical findings can change; revisit the primary sources before making a high-risk decision.