When you type a complex prompt into a cutting-edge artificial intelligence chatbot, you expect the answer to come from the neural network built by that specific company. If you log into an app created by a prominent Chinese AI developer, you reasonably assume you are conversing with their native model, honed by their own engineering and specialized datasets.
However, recent disclosures from cybersecurity researchers and U.S. technology labs have revealed a startling reality behind the curtain: in hundreds of thousands of cases, users were not interacting with native domestic models at all. Instead, their queries were being quietly rerouted to Western AI platforms, specifically Anthropic’s Claude.
The Discovery: Thousands of Rogue Accounts
The operational scale of this practice came to light when Anthropic detected suspicious traffic patterns hitting its servers. A sophisticated network consisting of thousands of fraudulent API accounts—operating across grey-market proxy networks in countries like Singapore and Japan—was systematically making millions of calls to Claude.
While a significant portion of this activity was focused on synthetic data harvesting (often referred to as model distillation to train domestic Chinese systems), investigators discovered an even more direct pipeline: real-time prompt relaying. Over short operational periods, prominent developers like Moonshot AI routed hundreds of thousands of live user requests directly into Claude, functioning as a silent proxy bridge.
To the end-user typing on their phone or laptop, the experience seemed seamless. The response was fast, polished, and remarkably coherent. What they did not know was that the intelligence generating that response belonged to a completely different platform miles away.
Why Shortcut the Intelligence?
Developing state-of-the-art foundation models is brutally expensive, computationally demanding, and time-intensive. High-level capabilities—such as multi-step chain-of-thought reasoning, advanced programming logic, and precise tool execution—require immense GPU clusters and refined reinforcement learning.
By quietly relaying complex or taxing queries to an industry-leading model like Claude, companies could maintain the illusion of possessing an ultra-capable AI assistant without incurring the massive computational cost needed to process those edge-case prompts internally. It allowed them to preserve server resources, retain users with high-quality answers, and artificially inflate the performance profile of their own platforms.
The Unseen Privacy & Security Trade-Offs
While getting a high-quality answer might sound like a win for the user on the surface, this proxy arrangement introduces severe privacy and security vulnerabilities:
- Unintended Data Exposure: Users submitting sensitive corporate code, business strategies, or personal records to a local app had no idea their data was being transmitted across borders to third-party American infrastructure.
- Broken Chains of Custody: When data flows through unauthorized proxy networks and middle-tier transfer stations, traditional encryption and privacy guarantees cease to function reliably. End users lose all visibility into where their information is stored or processed.
- Compliance Risks: Organizations utilizing these domestic platforms under strict local data sovereignty guidelines unknowingly violated their own governance policies due to the undisclosed transfer of data.
The Broader Impact on the AI Ecosystem
The exposure of these relay networks marks a turning point in the AI industry. It underscores the immense pressure on developers to demonstrate parity with top-tier foundation models, even if it means resorting to unauthorized pathways.
In response, leading AI vendors have tightened identity verification, blocked thousands of flagged proxy IP blocks, and shared threat intelligence across industry consortiums. For users and businesses, this incident serves as a clear reminder: in the rapidly evolving world of artificial intelligence, transparency regarding what happens under the hood is just as vital as the answer on your screen.
