Technology
OpenAI says it disrupted Moonshot-linked campaign to extract model reasoning
The company attributes a core cluster of “adversarial distillation” traffic to people associated with China’s Moonshot AI, developer of Kimi, after spikes of thousands of extraction-pattern requests in July.
Published: October 1, 2026 · 1 min read
OpenAI said it identified and disrupted a coordinated campaign to extract protected reasoning from its models — activity it described as adversarial distillation — and attributed a core cluster of that traffic to individuals associated with Moonshot AI, the Chinese startup behind the Kimi models.
In a Sept. 30 blog post, OpenAI said the earliest observed activity began in the first week of July and that high-volume spikes on July 24–25 included 16,000 requests using a relevant extraction pattern from more than 4,000 users. Related prompt-pattern activity spanned a cluster of more than 15,000 users before the company said it fully disrupted the campaign by July 28. Operators did not break encryption or access databases or stored conversations, OpenAI said; instead they manipulated model interactions so hidden reasoning could be reproduced in a form visible to the requester, including by copying encrypted reasoning between conversations and asking a model to transcribe it.
OpenAI said it was unclear whether all operators came from a single actor, but that a core cluster was linked to people associated with Moonshot. The company said it has shared findings through the Frontier Model Forum and government channels, closed a pathway that allowed replay of another user’s encrypted reasoning, and tightened account and infrastructure controls. Moonshot has previously faced distillation allegations from Anthropic; OpenAI’s post is its first public attribution tying Moonshot-linked accounts to this July campaign.
The episode sharpens the commercial and national-security fight over whether rivals can shortcut frontier training by harvesting another lab’s hidden chain-of-thought — and puts pressure on both U.S. and Chinese labs to prove that product gains are not built on unauthorized extraction.
Sources: OpenAI, “Disrupting a coordinated model-distillation campaign”; CNBC; Financial Post / Bloomberg.
Sources
Newsletter
News. Context. What matters.
One essential briefing, written for people who would rather understand the story than scroll it.
Unsubscribe anytime. We don’t sell addresses.
Recommended
Technology
Micrologic launches Canadian Sovereign Digital Vault for cyber-recovery data
Unveiled at Québec City’s Convergence 2026, the isolated Canadian-jurisdiction copy aims to help organizations restart after ransomware; $45-million from FTQ and Investissement Québec backs the build.
Technology
AWS open-sources Strands Decider 2B for fast local agent decisions
The 2-billion-parameter model, built on Qwen3.5-2B, scores predefined options with confidence instead of writing free text; weights are on Hugging Face under Apache 2.0.
Technology
SpaceX lofted Google TPUs to orbit in first Project Suncatcher AI test
Transporter-18 carried a Planet Labs solar-powered prototype with Alphabet’s tensor processors — an early check on whether space can host future machine-learning infrastructure.