Researchers: Chinese AI Startup Moonshot AI Acted as Wrapper for Anthropic's Claude
Security observers suggest Kimi users, including state-linked actors, may have unknowingly routed prompts to a U.S. AI firm.
A security researcher and industry observers have alleged that Moonshot AI, a leading Chinese AI startup, operated its Kimi chatbot as a "wrapper" for Anthropic's Claude model. The claims suggest that users interacting with Kimi were actually being routed to the American-made frontier model.
The allegations surfaced following an August 2025 threat intelligence report from Anthropic. The report detailed how nation-state actors, including those linked to China, misused Claude to conduct surveillance, influence operations, and cyberattacks. Security researcher David Agranovich and observer Ani Riley noted on X (formerly Twitter) that these actors may have been using Kimi, unaware that their prompts were being processed by Anthropic. Agranovich highlighted the irony of Chinese intelligence or military actors shipping sensitive prompts to a U.S. company because a domestic frontier AI was acting as a Claude wrapper.
The trend of model wrapping
This situation occurs against a broader industry backdrop of "model distillation" and "wrapping." In these practices, smaller or regional AI developers use the outputs of established frontier models, such as Claude or GPT-4, to enhance their own performance or maintain a high-quality user experience while their proprietary capabilities are still in development. By routing queries to a more powerful external model, a company can offer state-of-the-art results without having built the underlying architecture from scratch.
Security and sovereignty implications
If a prominent Chinese AI leader is found to be a wrapper for a U.S. model, the implications for national security are significant. It creates a scenario where sensitive, state-linked data is transmitted directly to a foreign competitor, potentially exposing strategic intentions or operational methods. Beyond security, such allegations cast doubt on the technical independence of regional AI leaders and raise questions about the authenticity of the benchmarks used to claim domestic parity with U.S. models.
Unconfirmed technicals
While the observations from researchers are documented, the exact technical nature of the routing remains unconfirmed. It is not yet clear if Moonshot AI officially integrated Claude as a wrapper or if the routing resulted from other technical configurations. Moonshot AI has not officially confirmed the nature of Kimi's backend architecture in relation to these specific claims.