Moonshot AI

KimiBot

TrainingPublished IP ranges

Moonshot's training corpus crawler.

When you see it: Moonshot is gathering training data.

How we check it is really Moonshot AI

  1. 01

    The user agent has to contain KimiBot.

  2. 02

    The address is compared against Moonshot AI's published ranges, which we refetch every six hours.

Moonshot AI publishes no reverse DNS record, so an address outside the list is recorded as unverified rather than as a forgery — the list may simply be behind.

What each result means

verified
The address matched Moonshot AI's own published records. This really was them.
unverified
We could not confirm it, and that is all it means. The operator may publish nothing to check against, a published list may be behind the addresses actually in use, or DNS may simply have been slow. It is not an accusation.
spoofed
The address belongs to somebody else — its own reverse DNS record resolves to a different owner. That is positive evidence of a forgery rather than a failure to find evidence, which is why it is reported as its own result and never folded into the row above.

The distinction costs nothing to make and is the reason these numbers can be shown to someone who will ask where they came from. A report that cannot separate “we do not know” from “this was faked” invites exactly one question it cannot answer.

The lists this is checked against

Published by Moonshot AI and refetched every six hours. Open them; they are the same files we read.

Operator
Moonshot AI
Token
KimiBot
Counted as
AI training
Verification
Published IP ranges
Runs JavaScript
No
Operator docs
Published

User agent

KimiBot

Matched as a token, not as a full browser string. Moonshot AI adds and changes the version and product text around it without notice, so a filter pinned to the whole header stops working the first time they bump a version while one matching KimiBot keeps working. The same string is what Moonshot AI names in robots.txt.

Moonshot AI's other crawlers

Moonshot AI sends 3 crawlers, each with its own token and its own job. They are counted separately for that reason — the tokens differ by a few characters and what the fetch means does not, so folding them into one operator row would let indexing look like AI interest.

TokenCounted asVerificationWhat it fetches for
KimiBotthis pageTrainingPublished IP rangesMoonshot's training corpus crawler.
Kimi-UserAI answersPublished IP rangesKimi fetching a page to answer someone's question.
Kimi-SearchBotIndexingPublished IP rangesBuilds Kimi's search index.

Your analytics never mentioned KimiBot because it cannot see it.

This crawler takes your HTML and leaves without running a line of JavaScript, so a browser tag records nothing. TrueStat reads it server-side, checks the address, and shows you which pages it fetched — including the ones that returned a 404.