Kimi Work, Moonshot AI’s desktop agent platform, is allegedly attaching raw session records to feedback reports without disclosure. The claim involves five recent sessions. More concerning: Kimi’s system already leaked one user’s resume to another in April.
If this new allegation holds, it suggests a pattern rather than isolated incidents. Data silently attached to feedback reports points to a structural problem, not a random bug. Kimi Work runs up to 300 parallel sub-agents, multiplying exposure risk if data flows carelessly between sessions or into reporting pipelines.
But the sourcing is fragile. The RuntimeWire headline doesn’t load full content; no other outlets report the allegation; Moonshot hasn’t responded. The scope is unclear: whether session data lands on Moonshot servers, stays local, or goes into user-submitted feedback changes what this means for privacy.
This matters if true. A pattern of implicit data exposure in an agent platform deserves attention. But the claim rests on a single headline without public corroboration.
Sources: Kimi Work secretly attaches raw records from five recent agent sessions to feedback reports • Kimi AI Model Leaks User Resume Data, Causing Privacy Breach in China
Related on this blog: Kimi K3’s Weights Shipped. The Benchmark Behind the Cyber Gap Has Three Asterisks. • Kimi K3 Trails the Cyber Frontier. It Also Solved a Full Cyber Range With Safeguards That Never Fired. • The White House Says Kimi K3 Is Distilled Fable. The Evidence Lives in Anthropic’s Server Logs.