8 Sources
[1]
OpenAI claims Moonshot extracted its data to train AI models.
In a blog post on Wednesday, OpenAI says it disrupted a "coordinated campaign designed to extract protected reasoning from our models." The company hasn't linked the activity to a single actor, but traced a "core cluster" of it to Moonshot, the Chinese company behind the leading AI model Kimi.
[2]
Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else
OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China's Moonshot AI of being involved in a "distillation attack" that began July 1. The house of Altman warns that extracting its models' reasoning at scale could help rivals
[3]
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to
[4]
OpenAI links China's Moonshot AI to attempt to extract its models' reasoning
* OpenAI said the activity surged to 16,000 requests from more than 4,000 users over two days, with related activity ultimately identified across more than 15,000 users. * The company said operators did not breach its encryption, databases or stored user conversations. * The findings come weeks
[5]
OpenAI says Moonshot-linked users tried to extract its AI reasoning
The Moonshot distillation campaign peaked at 16,000 requests in two days in July, OpenAI says. It has banned the accounts and shared its findings with rival labs and government. OpenAI says people linked to Moonshot AI, the Chinese developer of Kimi, were behind a coordinated campaign to extract
[6]
OpenAI disrupts Moonshot AI model reasoning theft campaign
The activity began in early July and surged to 16,000 requests from more than 4,000 users before OpenAI shut it down by July 28 OpenAI has announced that it detected and shut down a coordinated effort by operators to pull protected reasoning out of its AI models, with a central cluster of that
[7]
OpenAI Says Moonshot AI-Linked Users Tried to Extract its Models' Secret Reasoning OpenAI Says Moonshot A
OpenAI said individuals allegedly associated with Moonshot AI, the Chinese developer behind Kimi, were part of a broader campaign to extract "protected reasoning" from its AI models, using thousands of requests designed to reproduce information the company keeps hidden. "It is unclear whether all
[8]
Moonshot AI Of Kimi K3 Fame Tried To Crack OpenAI's Encrypted Reasoning Through 16,000 Requests, Bolstering Trump Administration's Distillation Claims
Once or twice can be a fluke, but thrice is a pattern, and OpenAI is now making sure that Moonshot AI - the lab behind the wildly successful Kimi K3 model - is tagged as a serial violator when it comes to orchestrating model distillation campaign, echoing similar calls from the Trump administration
Share
Copy Link
OpenAI disrupted a coordinated distillation campaign in July that peaked at 16,000 extraction attempts over two days. The company traced core activity to individuals associated with Chinese AI startup Moonshot AI, developer of the Kimi model, raising fresh concerns about AI model theft and national security risks.
OpenAI has accused individuals linked to Moonshot AI of orchestrating a coordinated campaign to extract protected reasoning from its AI models, marking the latest escalation in mounting tensions between US and Chinese artificial intelligence companies over data extraction and AI security practices.

Source: Hacker News
The adversarial distillation campaign began on July 1 at low volume before surging dramatically on July 24 and 25, when OpenAI detected 16,000 requests using extraction patterns from over 4,000 users
1
4
. Further investigation revealed related prompt-pattern activity across more than 15,000 users before OpenAI fully disrupted the coordinated campaign on July 282
3
. While the company could not definitively link all operators to a single actor, it traced a core cluster of the activity to individuals associated with Moonshot AI, the Chinese company behind the Kimi model5
.The operators did not break OpenAI's encryption, compromise databases, or gain direct access to stored user conversations. Instead, they manipulated model interactions to extract protected reasoning through a sophisticated technique
2
. According to OpenAI, attackers copied encrypted reasoning from one conversation, then prompted a model in another conversation to decrypt and transcribe it5
. This adversarial distillation represents the systematic and unauthorized use of one model's outputs to help train, reproduce, or improve another model without preserving the same safety guardrails3
.Researchers from MATS Research, ELLIS Institute Tübingen, and Synk identified an architectural vulnerability in August 2026 that made encrypted reasoning traces fully compatible across different sessions, users, and models within a provider's ecosystem
3
. By injecting an encrypted reasoning trace into a weaker, less safeguarded model from the same provider, attackers could force it to decode and output the trace in plaintext without directly jailbreaking the more capable model.OpenAI warned that adversarial distillation poses significant safety and national security risks. Extracted reasoning could be used to train another model without preserving safeguards applied to the original model's user-facing outputs
3
. At scale, distillation can accelerate the transfer of advanced capabilities without requiring the same investment in safety, concerns that become heightened as models gain capabilities in dual-use domains2
. Caroline Zier, who leads strategic national security policy initiatives at OpenAI, emphasized the company's concern centers on terms of service violation rather than open models or legitimate distillation5
.Related Stories

Source: The Next Web
This marks the first time OpenAI has directly accused Moonshot AI of data extraction attempts, though the Chinese startup faces similar allegations from other major AI companies
5
. Anthropic accused Moonshot AI last month of stealthily relaying customer requests to Claude instead of processing them using Kimi, then displaying Claude's responses back to users while retaining a subset of exchanges to train its chain-of-thought model3
. US President Donald Trump's Assistant for Science and Technology Michael Kratsios also accused Moonshot AI in late July of creating its Kimi K3 model by distilling Anthropic's Fable2
. Moonshot did not immediately respond to requests for comment on the allegations4
.
Source: The Register
OpenAI has deployed multiple countermeasures following the distillation attack. The company banned fraudulent accounts, tightened signup and infrastructure controls, and expanded monitoring efforts
2
. It closed a pathway that allowed someone who already possessed another user's encrypted reasoning to replay and recover its contents, and added checks to detect and hold streamed output that might expose reasoning3
. OpenAI shared investigation details with other AI firms through the Frontier Model Forum and government information-sharing programs2
4
.Anthropic's Claude Opus 5.5 model, released recently, includes a defense against distillation called preserved thinking that was introduced with Fable 5.1
2
. However, not everyone accepts these claims at face value. David Sacks, Trump's former AI czar, has characterized such reports as attempts to pressure the US into banning rival open models5
. Meanwhile, Chinese regulators are investigating both DeepSeek and Moonshot AI domestically, adding another layer of scrutiny to the companies' operations5
.Summarized by
Navi
[2]
11 Sept 2026•Technology

24 Jun 2026•Technology

13 Feb 2026•Policy and Regulation
