In brief

OpenAI said on September 30 that it had stopped a coordinated campaign to extract the hidden reasoning of its models. It attributes a core cluster of the activity to people associated with Moonshot AI, the Chinese developer of Kimi. The campaign peaked on July 24 and 25 with 16,000 attempts from more than 4,000 users, and OpenAI says it was fully disrupted by July 28.

New to this? Read it in simple words
  • OpenAI says some users tried to copy the hidden thinking of its AI models.
  • It says a core group of them were linked to Moonshot AI, a Chinese AI company.
  • OpenAI stopped the activity by July 28 and closed the gap they used.
  • OpenAI showed no proof of the link, and Moonshot has not answered publicly.
Words to know
Distillation
Training one AI model on the answers of another to copy its skills.
Hidden reasoning
The steps a model works through before it answers, which users do not see.
Attribution
Saying who is behind an attack or campaign.

What OpenAI saw

The activity began on July 1 at a low volume, OpenAI says. On July 24 and 25 it spiked to 16,000 requests from more than 4,000 users, and a wider cluster of more than 15,000 users showed related patterns.

The operators copied encrypted reasoning from one conversation and asked the model, in another conversation, to decrypt and transcribe it. OpenAI says they did not break its encryption, compromise a database or get direct access to stored conversations.

The figures describe attempts, not necessarily successful extractions, OpenAI notes. Outside security researchers separately reported related weaknesses, which it confirmed were real.

Sources12

CAMPAIGN TIMELINE 01
Four weeks from first sign to shutdown.

OpenAI’s own figures. They count attempts, not successful extractions.

“We attribute a core cluster of the activity to individuals associated with Moonshot AI,” OpenAI wrote. It added that it is unclear whether all the operators came from a single actor.

The post gives no technical evidence for the attribution, CyberScoop notes, and OpenAI told the outlet it would not share more for security reasons. CyberScoop asked Moonshot AI for comment, and we found no public response.

Moonshot has faced similar claims before. In February, Anthropic accused it, DeepSeek and MiniMax of large-scale copying, and on September 8 a joint US security advisory named it among six Chinese firms. China rejected the US claims.

Sources12

What OpenAI changed

OpenAI says it banned or restricted the accounts, tightened sign-up controls and closed the route that let someone replay another user’s encrypted reasoning. It also added checks that hold back streamed output that might reveal reasoning.

It shared its findings through the Frontier Model Forum, an industry group, and through government information-sharing channels. It says similar techniques may work against other companies’ models.

OpenAI calls distillation a safety and national-security risk, because a copied model may not keep the original’s safeguards.

Sources13

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Primary source · September 30, 2026Disrupting a coordinated model-distillation campaign OpenAI
  2. 2
  3. 3
    Research · September 30, 2026OpenAI Accuses Moonshot AI of Coordinated Model Distillation BankInfoSecurity
How we checked this story

We read OpenAI’s post and compared CyberScoop and BankInfoSecurity, which both rely on it. The numbers and the link to Moonshot are OpenAI’s alone, and no outside group has checked them. The earlier accusations come from CyberScoop’s reporting on Anthropic and the US advisory.