Angled close-up of a glowing teal circuit schematic panel on a dark surface, face-free cybersecurity still for Anthropic distillation and Moonshot IPO coverage

Anthropic says the cheap copies came off Claude

CNBC reported this morning that Anthropic’s head of threat intelligence, Jacob Klein, is calling out what he says is theft, not competition. Distillation — training a cheaper model on another lab’s outputs — can be legal. Klein says this isn’t. He told CNBC that Moonshot’s Kimi K3 was illegally trained off the newest Claude.

I don’t treat that as a court finding. It’s Anthropic’s allegation. Moonshot has disputed claims that K3’s performance came through distillation, according to Reuters via The Straits Times. The timing still matters. The same day Klein went on the record, sources told Reuters that Moonshot confidentially filed for a Hong Kong IPO.

Anthropic’s February 23 research post named DeepSeek, Moonshot, and MiniMax. The company says those labs generated over 16 million exchanges with Claude through about 24,000 fraudulent accounts. Distillation is normal when a lab distills its own models. Anthropic says this was the other kind: competitors grabbing capabilities they didn’t train, in a fraction of the time and cost.

Fake accounts, hydra proxies, dark web cards

Klein’s line to CNBC is the one that stuck with me: “There’s an entire illicit ecosystem to try to gain access to Claude and other models.” He says companies like Moonshot are “spinning up tens of thousands, if not hundreds of thousands of fraudulent accounts.” The tell, he says, is thousands of questions — not dozens — across thousands of accounts. The student model trains on the Q&A.

Anthropic’s write-up puts numbers on the earlier campaigns: DeepSeek over 150,000 exchanges; Moonshot over 3.4 million (agentic reasoning, tool use, coding, computer-use, vision); MiniMax over 13 million (agentic coding and tool orchestration). Access ran through “hydra cluster” proxies. One proxy network, Anthropic says, managed more than 20,000 fraudulent accounts at once. Anthropic does not currently offer commercial Claude access in China, so the alleged path is fake accounts and resellers. CNBC also describes dark-web marketplaces of stolen cards and compromised AI accounts. Travis Lanham at Armadin, a former Google engineer, told CNBC the traffic can hide inside billions of legitimate requests. Klein says slowing it down is still worthwhile. An April Trump administration memo called distillation that undermines American research and proprietary information “unacceptable.” Anthropic also accused Alibaba’s Qwen of a massive distillation attack; CNBC says those labs didn’t respond. OpenAI and Google have published their own reports claiming the same problem. Illicitly distilled copies, Klein and Anthropic both argue, may ship without the safeguards the original model was built with — that’s the national-security concern I’m willing to keep in view, without stretching the claim.

Cream-paper schematic of an alleged distillation path: hydra fake-account clusters feeding the Claude API, then student models at Moonshot Kimi, DeepSeek and MiniMax
Alleged path, not a verdict: hydra accounts into Claude, then cheaper student models. Schematic: Tech & AI Pulse.

Moonshot’s IPO week, still disputed

Reuters, via The Straits Times, says three people with knowledge of the plans report a confidential Hong Kong filing. One source said Moonshot is targeting about US$3 billion. I didn’t see a public prospectus. That’s a source talking. Two other sources put an ongoing funding round at a $50 billion valuation. CNA’s Reuters copy matches the confidential filing and the $3 billion target. Kimi K3 is a 2.8-trillion-parameter model, the reports say. Sources also described talks with Microsoft, Amazon, and Google on revenue-sharing — talks, not signed deals I’m treating as done.

Moonshot, founded in 2023 by Yang Zhilin after doctoral studies at Carnegie Mellon, has raised more than $5.5 billion, according to that Reuters account, with investors including Alibaba, Tencent, IDG Capital, and HSG. A May round of more than $2 billion came from Meituan, China Mobile, and CPE. Banks on the IPO, sources said, include Goldman Sachs, CICC, and Deutsche Bank. LatePost first reported the confidential filing on September 2. Moonshot did not immediately respond. U.S. Treasury Secretary Scott Bessent has said he might add the company to a trade blacklist. CNBC has reported Anthropic at close to a $1 trillion private valuation, with an IPO as soon as October — Reuters says Anthropic is planning an offering in the coming days and a listing by October.

From Mexico, I’m watching who owns the cheap copy

From Mexico, I’m less impressed by a cheap frontier model than by how it got cheap. Teams in Hermosillo will use whatever works. That’s rational. The risk Klein is pointing at is a copy trained through fake accounts and stolen cards, then sold without the original’s safeguards. Klein told CNBC competition is great. His concern is fraudulent means. I want ownership and safeguards in the same sentence as price. Cheap is good. Stolen capability with the guardrails stripped off is not a bargain.

Hero image: teal circuit panel by Adi Goldstein on Unsplash (Unsplash License). Cropped, graded, and lightly grained by Tech & AI Pulse.