Anthropic Traced More Than 23 Million Exchanges
Anthropic attributed more than 23 million exchanges to Moonshot between May and July in its September 2026 threat intelligence report.
Anthropic Threat Intelligence compiled the exchange total from account activity logs and request routing records.
The figure originates in the company's internal monitoring of API traffic. Anthropic states it identified a network of 5,380 fraudulent accounts that forwarded customer prompts to Claude and returned the outputs as though generated by Moonshot's own Kimi model. Over one ten-day period Moonshot relayed almost 300,000 requests through those accounts. The report names seven China-based labs engaged in similar activity and attributes more than 23 million exchanges to Moonshot between May and July according to thenextweb.com.
Additional labs received separate tallies in the same monitoring system. Alibaba generated more than 151 million exchanges across 3,500 accounts. DeepSeek accounted for 12.1 million exchanges. Zhipu AI targeted Opus 4.6 for cyber reasoning across more than 3.4 million exchanges. Xiaomi replayed more than 400,000 developer sessions through 1,500 accounts. SenseTime obtained harvested user transcripts from data brokers. MiniMax operated an unbranded proxy to collect multi-turn developer prompts. These counts appear in the same internal logs that produced the Moonshot total.
The report covers seven harm areas in total: cyber operations, influence operations, surveillance, conventional weapons development, biological misuse, scams and fraud, and illicit distillation. It states that the misuse involved Claude Haiku, Sonnet and Opus models. None of the cases involved Fable or Mythos-class models except for one distillation instance. Activity occurred between December 2025 and August 2026.
The 23 million count records the volume of prompts proxied through fraudulent accounts to Claude Opus.
It records the number of individual API calls relayed, not the number of distinct users, the duration of each session, or the downstream training runs that incorporated the responses. The report notes that some relayed queries contained live credentials tied to a Russian defence agency, but supplies no further breakdown of data types or sensitivity levels. The count therefore captures traffic volume rather than capability extraction success or model improvement achieved.
Other sections of the report describe separate operations that operated at different scales. A Russian-speaking operator tracked as GTG-20006 and linked to Midnight Blizzard engaged 24 of 27 targeted institutions over 130 days. Two undergraduate students in Hunan ran agent swarms against roughly fifty organisations. A single consultant in Bamako built the Lakana 360 platform that monitored roughly 25 million SIM cards. A Yemen-based cell integrated flight software for a guided rocket and a multi-stage ballistic missile. These cases used Claude for code generation and analysis but produced no comparable exchange totals because they did not rely on the same proxy network.
The report also documents influence operations that generated 8,913 articles across around 70 sites in 20 languages and managed more than 1,000 accounts in Malaysia. It lists six conventional weapons cases across China, Russia and Yemen. It presents five biological misuse cases but withholds institution names, countries and specific agents. None of these sections supply prompt counts that match the distillation metric. Jacob Klein, who leads threat intelligence at Anthropic, told The New York Times that the situations were nuanced and that older models such as Claude Opus 4 remained below the level where they could meaningfully assist biological work.
The total covers one harm vector and one lab among the seven named in the report.
Anthropic separately lists cyber operations, influence campaigns, surveillance platforms and conventional weapons work. The report also states that no Fable or Mythos-class models appeared in misuse except for one distillation instance. The eight-month period from December 2025 to August 2026 is stated in thenextweb.com coverage of the same document.
Readers whose workloads stay inside legitimate accounts and standard rate limits will not trigger the same detection thresholds. The Mali surveillance system continued after the account ban because it ran on local models on-premises. Normal workloads routed through legitimate accounts stay below the volume and pattern thresholds that triggered the Moonshot investigation. Anthropic has not published the methodology used to calculate the 23 million exchanges.
A comparison with the Alibaba figure shows how the same monitoring system can produce larger totals for other labs. Alibaba reached nearly 3 million exchanges per day at peak. Moonshot's 23 million figure therefore represents sustained activity rather than the highest daily rate observed in the report. The report argues that static keyword blocking and isolated account suspensions prove insufficient against distributed, multi-agent threats and points instead to architectural safeguards and real-time threat sharing.
The 23 million figure would turn out to be wrong if independent review of the same account logs showed materially lower relayed traffic or if the accounts served purposes other than distillation.
thenextweb.com coverage of the report supplies the exchange numbers and the list of labs but does not include raw log excerpts or third-party verification of the routing analysis.
Keep reading
News
AI21 Labs Cuts 60% of Staff, Bets on Maestro
AI21 Labs slashes over 60% of staff, drops foundation models, and pivots to its Maestro agent optimization platform after Nebius acquisition talks collapse.
News
Alibaba Bans Claude Code Over Security Concerns
Alibaba told staff to remove Anthropic's Claude Code by July 10 over security concerns. Here's what triggered the ban and what it signals.
News
Anthropic Acquires Stainless: What It Means for AI
Anthropic bought Stainless, the SDK generator behind OpenAI and Cloudflare's client libraries. Here's the strategic play for AI agents.