OpenAI disrupts "adversarial distillation" campaign linked to Moonshot AI associates
OpenAI says it disrupted a coordinated campaign to extract protected model reasoning, attributing a core cluster to individuals associated with Moonshot AI, the Beijing-based maker of Kimi.

OpenAI said on Wednesday it had identified and disrupted a coordinated campaign to extract protected reasoning from its AI models, attributing a “core cluster of the activity” to individuals associated with Moonshot AI, the Beijing-based Chinese AI company behind Kimi (http://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html). It cited no technical evidence, likely for security reasons.
The activity began on 1 July 2026 at low volume, then spiked on 24 and 25 July to 16,000 requests using a relevant extraction pattern from over 4,000 users. Related “prompt-pattern activity” reached more than 15,000 users before OpenAI shut it down on 28 July (https://enterpriseai.economictimes.indiatimes.com/news/industry/openai-alleges-chinese-ai-lab-used-distillation-to-extract-model-reasoning/134611599).
OpenAI stressed the operators did not break its encryption, compromise a database or gain direct access to stored user conversations. Instead, they manipulated model interactions so protected reasoning became visible to the requester: copying encrypted reasoning from one conversation and prompting a model in another chat to decrypt and transcribe it. OpenAI said it closed that “pathway” and added checks to detect and hold streamed output that might expose reasoning (http://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html).
OpenAI banned the fraudulent accounts, added mitigations, and shared its findings through the Frontier Model Forum and government information-sharing channels (https://www.tradingview.com/news/stocktwits:c6e3292b4094b:0-openai-accuses-kimi-operator-china-s-moonshot-ai-of-copying-ai-model-reasoning/).
“Adversarial distillation poses safety and national security risks,” OpenAI said. “Extracted reasoning could be used to train another model without preserving the safeguards applied to the original model’s user-facing outputs” (http://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html).
The allegations follow similar claims last month from Anthropic, which accused Chinese AI developers including Moonshot AI and Alibaba of distilling its Claude models (http://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html). Moonshot AI has not responded (https://startupfortune.com/openai-accuses-moonshot-ai-of-running-a-campaign-to-steal-its-model-reasoning/).
More on this topic: all Technology stories

