OpenAI has disclosed that it disrupted a coordinated July campaign aimed at illicitly extracting the “protected reasoning” of its frontier artificial intelligence models, attributing a core cluster of the activity to individuals associated with Beijing-based Moonshot AI, the developer of the Kimi chatbot.[2][1][3][4]
According to OpenAI, the earliest activity tied to the campaign appeared in the first week of July 2026 and initially ran at low volume before surging later in the month.[2][6][10] On July 24 and 25, the company logged roughly 16,000 extraction-pattern requests from more than 4,000 user accounts, a spike that helped investigators uncover related behavior across over 15,000 accounts in total.[1][5][13][15] OpenAI says it cut off the campaign by July 28, blocking the identified accounts and neutralizing the specific extraction methods operators were using.[2][7][8][15]
The operators did not break encryption, compromise databases, or gain direct access to stored user conversations, but instead manipulated how they interacted with the models to surface hidden reasoning.[2][3][9][10] OpenAI reports that one tactic involved copying encrypted reasoning from one conversation and pasting it into another, then prompting a separate model instance to decrypt and transcribe that content, effectively turning concealed chain-of-thought into visible output.[6][14][15] The company describes the overall activity as “adversarial distillation,” meaning systematic, unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model.[2][6][10]
While OpenAI stops short of saying all operators were directed by a single entity, it attributes a core cluster of the campaign to individuals associated with Moonshot AI, whose Kimi assistant competes with OpenAI’s products.[2][3][4][11] That attribution lands against a broader backdrop of concern about Chinese AI firms distilling Western frontier models: a recent advisory from U.S. cybersecurity authorities warned that China-based companies, including Moonshot AI, have conducted wide-scale distillation against U.S. AI providers since at least mid-2025, extracting Claude Fable 5 and GPT-4o data to train Kimi-K3 and Kimi-K2.[12] Together, the advisory and OpenAI’s account suggest an industrial-scale effort to copy not just responses but underlying reasoning structures from leading models.[2][4][12]
OpenAI frames the incident as an intellectual property and model integrity risk rather than a traditional data breach, stressing that users’ stored conversations and backend systems were not directly exposed.[2][3][9] Even without database compromise, however, successful reasoning extraction could erode the competitive moat around frontier models and undermine safety architectures if hidden reasoning contains alignment strategies or guardrail patterns that can be replicated elsewhere.[1][4][8] The episode underscores how model-output abuse and API misuse are becoming as central to AI security as software vulnerabilities are to conventional systems.[1][6][14]
In response, OpenAI says it has tightened technical safeguards, restricted or closed implicated accounts, and shared indicators of the activity with partners and relevant authorities to help others detect similar distillation attempts.[2][10][15] The company also signals plans to expand detection for extraction patterns, harden controls around access to advanced reasoning capabilities, and refine terms of service to address systematic adversarial distillation more explicitly.[2][6][14] For organizations operating or integrating large language models, the case highlights the need to monitor usage at scale for suspicious patterns, constrain exposure of hidden reasoning, and treat model-output abuse as a core threat in AI security programs.[1][5][8]
References
- OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
- Disrupting a coordinated model-distillation campaign
- OpenAI links China’s Moonshot AI to extraction attempt
- OpenAI Blames Moonshot for Mass Data Extraction on Its …
- OpenAI Links AI Model-Extraction Campaign to Moonshot, Disrupts Network of 15,000 Users
- OpenAI says Moonshot-linked users tried to extract its AI …
- OpenAI Names Moonshot-Linked Reasoning Extraction
- OpenAI says actors linked to China-based Moonshot AI spearheaded a campaign to extract its models’ hidden reasoning — logged 16,000 extraction requests across 4,000 accounts before cutoff
- The Hacker News | #1 Trusted Source for Cybersecurity News
- tokenpost.com · news · technologyOpenAI Links Moonshot AI Associates to Reasoning-Extraction…
- OpenAI Says It Disrupted a Reasoning-Extraction …
- China-Based Artificial Intelligence Companies Conducting …
- Kimi AI trained on ChatGPT? OpenAI accuses Moonshot of massive AI model copying campaign
- OpenAI Links Moonshot Users to 16000-Request …
- OpenAI Links Large-Scale Reasoning Extraction Campaign to Moonshot AI
