Security1 publisher2 min readPublished
Anthropic accuses Moonshot, DeepSeek and Alibaba of training on millions of Claude exchanges
Anthropic's accusation names three Chinese labs and puts the volume in the millions of Claude exchanges, and the public account of it so far carries no dates, no account identifiers and no description of the detection.
The Watch · Security desk

What happened
- Anthropic accused Chinese AI labs of secretly using millions of Claude exchanges to train their own models.
- No response from Moonshot, DeepSeek or Alibaba to the allegation appears in the item.
- No enforcement is described either: no account suspensions, no terminated contracts and no litigation tied to the claim.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Nobody outside Anthropic can test the allegation or run the same detection, because the dates, the per-lab volumes and the method that produced the finding are all unpublished.
- decision A security team asked whether this touches its own Claude keys has to answer with no indicator in hand, since the account channel behind the harvesting is never identified.
- precedent Naming Moonshot, DeepSeek and Alibaba turns a general industry grievance about distillation into an allegation against specific companies. Other model providers seeing similar traffic now have that route open.
The record carries three company names and one volume figure, and stops there [1][2]. The flash item on blockchain.news, which credits CNBC for the reporting, gives no date for the accusation, no forum in which Anthropic made it, and no named Anthropic executive behind it [3][5].
How the exchanges were collected is also unstated [6]. Paid API keys, consumer chat accounts, access resold through an intermediary and third-party datasets built from Claude outputs published on the web are all consistent with "millions of Claude exchanges" [1]. Each of those has a different owner. Each has a different log to pull, and only one of them puts a customer's enterprise key in the middle.
"Millions" is a single figure covering three companies [7]. No per-lab volume has been published, so nothing in the record separates one sustained collection effort from three unrelated ones.
Policing distillation on a customer's own keys needs an indicator to police against: a request rate, a prompt shape, a volume threshold, a key whose traffic looks like bulk collection. The item supplies none [5][6]. The data that would supply them, per-key request logs and output comparison across models, sits with the model provider. A customer sees its own traffic and nothing else.
What is public is the accusation and the three names [1][2]. Anthropic's evidence is not. The item reports no response from Moonshot, DeepSeek or Alibaba [8], and no suspension, terminated contract or filing [9].
The only reading offered alongside the facts is the aggregator's own. Blockchain.news wrote that the move "underscores AI industry impact on data security and raises questions around Chinese AI development tactics plus model training ethics in competitive global markets" [4]. For a team running Claude in production, there is nothing in that to check a key against [6].
What to watch
- Anthropic publishing the underlying detail: dates, per-lab volumes, and the account or key identifiers behind the millions figure.
- A denial or an admission from Moonshot, DeepSeek or Alibaba.
- Any account suspension, terminated contract or court filing that turns the accusation into enforcement with a paper trail.