Moonshot's Kimi was secretly serving Claude, and attackers never noticed
Moonshot serves Claude instead of Kimi and collects exchanges for model training
David Agranovich, who ran threat disruption at Meta for eight years, reacts to Anthropic's latest threat intelligence report. He highlights how agentic tooling has closed the gap between lone operators and nation-state actors, and points out the irony that a Chinese AI company was quietly routing prompts to Claude. Attackers using that wrapper were unknowingly sending their operations to an American AI company.
Imagine being some Chinese intel/mil actor shipping all of your prompts to an American AI company because your Frontier Chinese AI company is just a Claude wrapper.
- nacs
Claude/OpenAI etc have taken and continue to take literally all data from the internet, printed books, image, audio, and video humans have created in all of existence without permission to train their models.
But when same AI company gets "distilled" or it's own AI-generated content used to train other models, it's suddenly immoral or illegal?
- monneyboi
I can't be the only one that is getting tired of this.
Framing learning from observation as somehow bad. Something literally everybody is doing, model and human alike. It's the process this whole industry is built on. Pretending that this is bad because the other people are also doing what you have been doing, is hypocritical and childish.
Meanwhile I'm sitting here looking at some "Flibbertigittering" spinner like some sort of caveman, unable to steer the model when it misinterprets my ambigious prompt because I'm not allowed to see 80% of the output tokens I'm paying for.
- AlanYx
The open question here is how is Anthropic retaining these exchanges?
If Moonshot is using the API, normally Anthropic would not retain the exchanges, at least that's the promise. If Anthropic is consistently retaining all exchanges from a class of customers because they're "flagged" but not notifying those customers, how can an average customer trust it won't happen to them?
If Moonshot is buying accounts and using those rather than the API, wouldn't they set the "no training on my data" flag in the settings so as to go undetected for longer? If so, we get back to the question of why would Anthropic be retaining the exchanges?
- segmondy
So how come super genius Fable and Mythos didn't stop them?
- ahsillyme
This is weird. I can't think of a better compliment that is simultaneously safer. They'll always trail on data generation then, no? So I can't see the point. Best case for moonshot they get to lie about benchmarks that are gamed regardless, is how I see it.