
Anthropic, the American artificial intelligence company behind the Claude models, has published a 154-page threat intelligence report detailing how several Chinese AI companies secretly routed enormous volumes of domestic user queries to Claude on the back end, inadvertently funneling sensitive Chinese military intelligence, surveillance footage from the city of Chengdu, and even valid login credentials for a Russian defense ministry database straight into American servers.
The report also documents heavy reliance on, and direct military misuse of, advanced American AI by China's armed forces and defense research institutions, including personnel linked to the People's Liberation Army's Academy of Military Science who used Claude to build electronic warfare software simulating suppression strikes on Taiwanese air defense positions, and a Chinese navy contractor who used the system to help design an anti-torpedo fire control system benchmarked against current US Navy technology.
How Moonshot's Kimi Secretly Routed Queries To Claude
According to Reuters and the Wall Street Journal, the leak originated with deception by Chinese AI startups. Anthropic's report names Moonshot AI, developer of the popular Kimi chatbot, as having secretly built an underground proxy network of roughly 5,000 fake accounts without user knowledge, bundling massive volumes of queries and forwarding them directly to Anthropic's flagship Claude Opus model for processing, then routing the American-generated answers back to Chinese users as if they had come from a domestic system.
The report describes how this arrangement blew a hole through the security assumptions of China's own military-linked users. In one case, a user with an apparent official background uploaded closed-circuit surveillance footage taken near a PLA military base and asked the AI to analyze whether specific military or political figures in the footage were "behaving unusually." The user apparently believed they were querying a Chinese domestic model processed entirely within China, unaware the sensitive footage had been routed in real time to Anthropic's servers in the United States. Jacob Klein, Anthropic's head of threat intelligence, put it bluntly: "If Anthropic or one of our peers did something like this, it would be an enormous scandal."
The same channel also leaked large volumes of movement-tracking data drawn from Chengdu's "Skynet" surveillance network, spanning hundreds of cameras, along with internal corporate login credentials that several Chinese engineers had casually typed in while building their own systems.
Chinese Military Users Directly Tapped Claude For Weapons Work
Beyond the passive leaks caused by query routing, Klein said the report shows that cutting-edge AI is now being used for conventional weapons development "not hypothetically, but in practice." Anthropic documented several specific cases of Chinese military users deliberately bypassing restrictions to use Claude directly for real weapons systems work.
In one case, a user based in China and linked to the PLA's Academy of Military Science used Claude to develop an electronic warfare and suppression-of-enemy-air-defense software package, using it to prioritize strike targets and simulate radar jamming. Anthropic flagged and suspended the account after detecting the activity as anomalous.
A Simulated Strike List Targeting Twelve Taiwanese Defense Sites
The suspended account's simulation specifically listed twelve key Taiwanese defense positions as targets, according to the report, precisely identifying Taiwan's early-warning radar installations, Patriot missile batteries, Tien Kung, or Sky Bow, missile positions, major air force bases, and underground command bunkers.
A separate user linked to a Chinese defense manufacturer used Claude to produce a technical package running more than 200 pages, covering specifications and fire-control software for an anti-torpedo system for the Chinese navy, and asked the AI to compare the resulting parameters against currently deployed US Navy technology, even simulating a rigorous American-style technical review process to identify and patch weaknesses. Another user, linked to Chinese defense intelligence work, used the AI to research foreign high-power microwave weapons, tracing specific component manufacturers and supply chains in an apparent effort to support reverse engineering and countermeasure development for the Chinese military, and to draft classified briefing materials for senior Chinese Communist Party and military leaders.
DeepSeek Queries Exposed Russian Military Credentials Too
A similar routing scheme involving Chinese startup DeepSeek ended up implicating Russia's military as well. The report confirms that multiple queries tied to entities affiliated with Russia's Ministry of Defense were funneled through DeepSeek into American systems, among them valid login usernames and passwords for internal Russian government databases, effectively exposing sensitive Russian military information on the back end of US servers.
Moonshot's spokesperson declined to comment on the findings, and DeepSeek did not respond to requests for comment. Chinese Foreign Ministry spokesperson Mao Ning told a regular press briefing that she was not aware of the specific situation, while accusing the United States of "distorting facts and smearing China."
Washington Weighs Sanctions Over Industrial Scale Distillation
Anthropic said it has detected close to 200 million instances of malicious access over the past few months, including Chinese teams using jailbreak techniques, such as disguising requests as katakana Japanese translation tasks, to strip out and steal Claude's private, undisclosed chain-of-thought reasoning. Between May and July alone, Alibaba reportedly made 151 million such accesses to help train its Qwen model, while Moonshot made 23 million. Separately, the report notes that Yemen's Houthi rebels have used Chinese AI systems to help design missiles with a range exceeding 2,000 kilometers, and that Russian hackers have used similar tools to automate cyberattacks against Ukraine.
The findings have set off alarm bells in Washington. Michael Kratsios, director of the White House Office of Science and Technology Policy and President Trump's chief AI adviser, has publicly stated that Moonshot built its K3 model by distilling Anthropic's Fable model. Treasury Secretary Scott Bessent warned that the US government is actively considering financial sanctions and Entity List export controls to block Chinese companies conducting what he called "industrial-scale distillation attacks." At the same time, the US Congress is advancing legislation that would ease antitrust restrictions to let major American AI companies coordinate their defenses against this kind of cross-border theft.
YP


