Story
October 2, 2026
OpenAI says it stopped a Moonshot-linked push to copy its hidden AI reasoning
OpenAI says a July campaign used thousands of requests to draw out protected model reasoning, with a core cluster tied to people associated with Moonshot AI. The company says no systems were breached, but warns the tactic could let rivals shortcut costly safety work.
OpenAI says the campaign began quietly in the first week of July, with operators attempting to turn the internal working traces of its models into readable material. The company calls the technique “adversarial distillation”: using another model’s outputs or reasoning to train, reproduce or improve a competing system.1
The distinction matters. OpenAI says the operators did not crack encryption, breach databases or access stored user conversations. Instead, they manipulated model interactions—at times copying encrypted reasoning from one conversation and asking a model in another to decrypt and transcribe it. In OpenAI’s view, that is a serious route around the investment and safety controls behind advanced models, not a conventional systems intrusion.1
The activity accelerated sharply on July 24 and 25, when OpenAI recorded 16,000 extraction-pattern requests from more than 4,000 users. Its subsequent investigation found related prompt activity across a cluster of more than 15,000 users; by July 28, it said, the campaign had been fully disrupted through account restrictions, technical controls and coordination with partners.1
OpenAI says it cannot establish that every operator belonged to one actor. But it attributes a “core cluster” to individuals associated with Moonshot AI, the Chinese developer of Kimi. Reporting on the allegation noted that Moonshot did not immediately respond to requests for comment, leaving OpenAI’s attribution unaddressed publicly.2
The accusation lands amid a broader industry fight over model copying. Anthropic had already accused several Chinese AI developers, including Moonshot, of using Claude to assist training efforts; another report said OpenAI’s claim echoed those earlier allegations.3 OpenAI has shared its findings with the Frontier Model Forum and government channels, arguing that the defense against reasoning extraction must be collective as such tactics become cheaper and more sophisticated.1