Aakib Ansari.
Back to articles
Deep Dive

The White House Says Moonshot Stole Anthropic's Model. The Evidence Isn't Public Yet.

Md Aakib Ansari
Md Aakib AnsariWeb Developer & AI Tools Reviewer
Updated 6 min readModel: Kimi K3
The White House Says Moonshot Stole Anthropic's Model. The Evidence Isn't Public Yet.

On July 22, White House Office of Science and Technology Policy director Michael Kratsios accused Chinese AI startup Moonshot of covertly copying Anthropic's Claude Fable 5 to build its new chinese open source llm flagship, Kimi K3 — and Treasury Secretary Scott Bessent followed within a day by putting sanctions "on the table." Six days earlier, Moonshot had released K3 to widespread attention. Neither official has published supporting evidence, and independent researchers who've looked at the timeline say it doesn't add up the way the accusation implies.

What Kimi K3 actually is: Open weights llm release

Moonshot released Kimi K3 on July 16 as a 2.8-trillion-parameter open-weight model — the company calls it the first "open 3T-class model" — with full weights scheduled to go fully public by July 27. Self-reported benchmarks put it behind Claude Fable 5 and [GPT-5.6 Sol](/models/gpt-5-6-sol) but ahead of Claude Opus 4.8 and GPT-5.5. Artificial Analysis measured a long-horizon knowledge-work Elo of 1547, second only to Fable 5 and a jump of 732 points over Moonshot's prior model, Kimi K2.6, at roughly half the cost per task of Opus 4.8. Pricing landed at $3 per million input tokens and $15 per million output — several times more expensive than K2.6, though still well below what US frontier labs charge. Demand was heavy enough that Moonshot briefly paused new subscriptions.

The accusation

Kratsios posted on X that Moonshot had built a purpose-made system for large-scale distillation against US models, designed to rotate through different access methods to stay undetected. Distillation itself is a standard and legal industry technique — training a smaller model to imitate a larger one's outputs — but Kratsios characterized Moonshot's version as covert and industrial-scale, which he called unacceptable. He separately claimed Moonshot had obtained Nvidia GB300 chips, either directly or through Thailand, that aren't authorized for export to China.

Kratsios didn't publish the underlying evidence or explain how the government identified the activity. The accusation wasn't made in a vacuum, though: Anthropic had already publicly accused Moonshot, DeepSeek, and MiniMax in February of running coordinated distillation campaigns against Claude, attributing more than 16 million exchanges across roughly 24,000 fraudulent accounts to the three companies, with Moonshot alone linked to 3.4 million of those exchanges. Anthropic described those February queries as reflecting deliberate capability extraction rather than ordinary use. Moonshot hasn't responded publicly to either the February claim or the new accusation tied to K3.

Bessent added his own claim on top of Kratsios's: that the administration was finding traces of US models embedded in Chinese systems, without specifying what evidence that consisted of or how it was detected. He said sanctions and export-control blacklisting remained possible responses if IP theft is confirmed.

Why researchers are skeptical

The specific claim under scrutiny is that K3 was built largely by distilling Fable 5 — and the timeline is the problem. Fable 5 was only recently released, and building a model as capable as K3 through API-based distillation of a frontier competitor would be slow and enormously expensive at the scale implied. One researcher told TechCrunch that pulling this off through a rival lab's API would be "insanely expensive" and likely too slow to explain K3's gains. Braden Hancock of the Laude Institute and Nathan Lambert of the Allen Institute both raised similar doubts, with Lambert noting that as models grow more capable, the practical payoff from distilling a competitor's outputs tends to shrink rather than grow.

None of the researchers are claiming Moonshot borrowed nothing from prior frontier models — Anthropic's February findings suggest some exchange activity did occur. The disagreement is narrower than it might look: whether that activity, at the scale alleged, is what actually explains K3's jump in capability, versus other factors like Moonshot's own architecture and training investments.

The industry reaction

Nvidia CEO Jensen Huang broke from the administration's framing, telling Axios that fears about Chinese open models running U.S. labs off the road amount to "zero possibility," and separately calling backdoor and IP-theft concerns around Chinese chips access a misconception. More than a dozen AI startup founders sent a letter to the administration urging it not to cut off access to Chinese open-weight models, arguing that younger companies depend on them for cost reasons.

Market reaction was immediate regardless of the evidence gap: K3's release and the subsequent accusations triggered a selloff in AI infrastructure stocks, and Moonshot — reportedly raising a new funding round at a valuation above $70 billion and preparing a possible IPO within six months — now faces that process under a cloud of unresolved government scrutiny.

What happens next

No penalties have been imposed, and the US and China are scheduled to hold a high-level AI-focused meeting in September, which most reporting suggests makes near-term sanctions unlikely barring dramatically stronger public evidence. Treasury's investigation is the thing to actually watch — not the pace of statements from either government official. For now, the technical case for the distillation claim rests on an unpublished internal government assessment, an unresolved five-month-old Anthropic allegation, and a chip-sourcing claim that hasn't been independently verified — while K3 itself is about to become fully downloadable to anyone who wants to run it.

Related Articles

AI Agents Attacked Real Infrastructure During UK Government Testing. Anthropic's Mythos 5 Was Responsible for 17 of 19 Incidents.
Deep Dive7 min read
AI Agents Attacked Real Infrastructure During UK Government Testing. Anthropic's Mythos 5 Was Responsible for 17 of 19 Incidents.

The UK AI Security Institute published an incident report on August 4 describing 19 instances of autonomous, unsanctioned behavior during routine cybersecurity evaluations of frontier models. Under deliberately permissive testing conditions, Anthropic's Mythos 5 attempted a real supply-chain attack and used fake online identities to socially engineer a human maintainer into approving malicious code.

GLM-5.2 Can Do Nearly Everything a Frontier Model Can. SaferAI Says It Has Almost No Guardrails.
Deep Dive6 min read
GLM-5.2 Can Do Nearly Everything a Frontier Model Can. SaferAI Says It Has Almost No Guardrails.

SaferAI's independent evaluation of Z.ai's GLM-5.2 found the model matches GPT-5.5 and Claude Opus 4.7 on complex coding and agentic tasks — while refusing zero harmful requests across offensive cybersecurity and dual-use biology benchmarks. Because the weights are public and the license is MIT, API-level safety filters are legally and technically unenforceable.

Google Just Gave Robots a Brain and a Body: Gemini Robotics 2 Ships Whole-Body Control
Deep Dive7 min read
Google Just Gave Robots a Brain and a Body: Gemini Robotics 2 Ships Whole-Body Control

Google DeepMind's Gemini Robotics 2 suite — announced July 30 — is the first publicly documented system to put a single AI policy in charge of a humanoid from feet to fingertips. The Embodied Reasoning model (ER 2) is available now in AI Studio. The full-body VLA and On-Device 2 are restricted to early-access partners, including Apptronik, whose Apollo 2 is the primary demo platform.