OpenAI said people tied to Chinese rival Moonshot AI were at the core of a campaign to extract its models' hidden reasoning, which peaked at 16,000 requests in July. Key Points: OpenAI tied a
OpenAI said people tied to Chinese rival Moonshot AI were at the core of a campaign to extract its models' hidden reasoning, which peaked at 16,000 requests in July.
Key Points:
- OpenAI tied a core cluster of the July activity to people associated with Moonshot, the developer of Kimi.
- The operators copied encrypted reasoning between chats but did not break OpenAI's encryption.
- Moonshot has not publicly responded, and China has rejected earlier distillation claims.
OpenAI Accuses Moonshot
OpenAI disclosed the findings in a blog post on Wednesday. The activity started at low volume on Jul. 1, the company said. It spiked on Jul. 24 and 25, when more than 4,000 users sent 16,000 requests using a matching extraction pattern.
The company later found related activity across more than 15,000 users and fully shut the campaign down by Jul. 28.
It could not tie every operator to one actor but attributed a core cluster to people associated with Moonshot, the Chinese developer of the Kimi models.
OpenAI hides its models' reasoning before they answer. The operators copied that encrypted text from one conversation and asked a model in another chat to transcribe it, OpenAI said, though they never broke the encryption or reached stored user conversations. It has since banned the accounts, tightened sign-up checks and shared its findings with other AI labs and government channels.
Also Read:Bitget Restores Protection Fund Above $300M As Withdrawals Resume
OpenAI Distillation Concerns
Caroline Zier, who leads strategic national security policy initiatives at OpenAI, said the company objects to breaches of its terms of service, "not open models or legitimate distillation."
Distillation itself is common across the industry. In its post, OpenAI warned that extracted reasoning could train a rival model without the original safeguards, moving advanced capabilities "without requiring the same investment in safety." David Sacks, President Donald Trump's former AI czar, has called such reports an attempt to get Washington to ban open models that challenge the business of OpenAI and Anthropic.
Moonshot Kimi Scrutiny
Moonshot has not publicly responded to the claims. China's government has rejected earlier distillation accusations from US firms and the Trump administration, and it has warned that it would retaliate against any US penalties.
Moonshot launched its Kimi K3 model on Jul. 16. Within weeks, White House science adviser Michael Kratsios said the company had accessed Nvidia Blackwell servers barred from sale to Chinese firms and pulled data from US models. Then on Sept. 10, Anthropic reported that Moonshot had secretly routed about 300,000 user requests to its Claude models through 5,380 fraudulent accounts.
Read Next:Dogecoin Is Getting An App Layer After 12 Years Without One