How Moonshot AI's Kimi Got Caught in the US-China AI Espionage Spotlight
The US National Security Agency, Cybersecurity and Infrastructure Security Agency, and FBI have accused Moonshot AI of conducting large-scale extraction operations against American AI models, specifically using Claude and GPT data to train its Kimi chatbot systems. In a joint advisory published on September 8, 2026, the agencies named six Chinese AI companies, including Moonshot AI, as participants in what they describe as industrial-scale distillation campaigns designed to steal proprietary capabilities from leading US frontier models.
What Exactly Is Moonshot AI Accused Of Doing?
According to the NSA, CISA, and FBI advisory, Moonshot AI is specifically accused of extracting Claude Fable 5 data to train its Kimi-K3 system, while also using GPT-4o data to train Kimi-K2. The agencies allege that Moonshot AI, along with five other firms, ran continuous, high-volume queries designed to extract proprietary capabilities, reasoning patterns, and specialized functions from US frontier models. These weren't casual interactions; the agencies describe organized, systematic campaigns involving billions of tokens extracted across millions of exchanges and requests.
The allegations paint a picture of sophisticated infrastructure designed to avoid detection. According to the advisory, the companies allegedly used fraudulent accounts, bulk procurement of premium subscriptions, and proxy services known as "transfer stations" to bypass regional restrictions and provider safeguards. These transfer stations reportedly resold access to US models at reduced prices while obscuring identifying metadata, allowing operators to distribute requests across multiple pathways and automatically switch between them during blocking attempts.
How Did These Extraction Campaigns Actually Work?
- Fraudulent Account Networks: The companies created thousands of fake accounts to access US AI models without triggering standard detection systems, with Anthropic previously disclosing that three Chinese AI laboratories generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.
- Bulk Subscription Purchases: Rather than using individual accounts, the firms allegedly bought premium subscriptions in bulk to gain high-volume access to proprietary models and their advanced features.
- Transfer Station Routing: Proxy services resold access to US models at reduced prices while hiding the true origin and purpose of requests, making it harder for AI companies to identify and block malicious activity.
The routing infrastructure allowed operators to distribute requests across multiple pathways and automatically switch between them when providers attempted to block suspected offenders. This technical sophistication suggests that the campaigns were not ad hoc efforts but rather coordinated operations with significant resources and planning behind them.
Why Should Users Care About Moonshot AI and Kimi?
The accusations against Moonshot AI matter for several reasons. First, they raise questions about the integrity of AI models available to consumers and enterprises. If Kimi-K2 and Kimi-K3 were trained using improperly extracted data from Claude and GPT models, their capabilities may be built on intellectual property that was obtained without authorization. Second, the allegations highlight a broader pattern of AI model theft that could reshape how AI companies protect their systems and interact with users.
The US agencies also revealed a controversial countermeasure they're recommending to US AI companies. Rather than simply blocking suspected offenders, companies are advised to subtly alter responses or use less sophisticated models for users identified with high confidence as conducting malicious distillation, without informing those users of the change. This raises transparency concerns for everyday users, as they might receive degraded AI responses without knowing why.
Is This the First Time Moonshot AI Has Faced Such Accusations?
No. This is part of a longer pattern of allegations against Chinese AI firms. Anthropic previously disclosed in 2026 that three Chinese AI laboratories, including Moonshot AI, had generated millions of exchanges with Claude through fraudulent accounts. The White House Office of Science and Technology Policy also noted in an April 2026 memorandum that models developed through unauthorized distillation campaigns "do not replicate the full performance of the original," although they can appear comparable on selected benchmarks.
The September 2026 advisory brings together the alleged activities of six companies, including Moonshot AI, DeepSeek, Alibaba, MiniMax, StepFun, and Z.AI, in a single assessment by three major US intelligence agencies. The agencies say the activity dates back to at least late 2024 and was carried out "likely with the knowledge of the Chinese government".
What Does This Mean for the Broader AI Industry?
The accusations form part of an escalating US-China AI rivalry, in which the ability to develop frontier models faster and more cheaply has become a matter of national strategy as well as commercial advantage. The agencies argue that industrial-scale distillation allows Chinese AI companies to extract capabilities from US frontier models while reducing the research, computing, and development resources required to build comparable systems independently.
At the time of publication, none of the six named companies, including Moonshot AI, had issued a public response to the specific allegations. The lack of response leaves many questions unanswered about how Moonshot AI plans to address these accusations or whether it will provide evidence contradicting the US intelligence agencies' claims.