OpenAI Ties Reasoning-Extraction Campaign to Moonshot AI, 64 Days After Shutting It Down
A.I. / news
OpenAI Ties Reasoning-Extraction Campaign to Moonshot AI, 64 Days After Shutting It Down
The company says 16,000 requests from 4,000 users peaked on July 24 and 25. It published on September 30 and attributes only a core cluster to Moonshot.

OpenAI said on Wednesday that it disrupted a coordinated campaign to extract the hidden reasoning of its models, and that a core cluster of the activity traces to people associated with Moonshot AI, the Chinese developer of the Kimi models. The company shut the campaign down by July 28 and published its account on September 30, a gap of 64 days.
The post, titled "Disrupting a coordinated model-distillation campaign", was published at 10:30 GMT, according to OpenAI's news feed. OpenAI's own page returned a bot-challenge screen when fetched, so the detail below comes from the feed summary and from two outlets that read the full post: The Next Web and FourWeekMBA.
What OpenAI says happened, and when
The activity began on July 1 at low volume. It spiked on July 24 and 25, when OpenAI counted 16,000 requests from more than 4,000 users. The company then found related activity across more than 15,000 users before closing it out on July 28.
| Date | What OpenAI reports |
|---|---|
| July 1 | Activity begins at low volume |
| July 24 and 25 | 16,000 requests from more than 4,000 users |
| July 28 | Campaign fully shut down |
| September 30 | Public disclosure |
OpenAI calls this adversarial distillation, which it defines as "the systematic and unauthorized use of one model's outputs or reasoning to help train, reproduce, or improve another model", as quoted by The Next Web.
How the extraction worked
The operators copied encrypted reasoning from one conversation. They then asked a model in a separate conversation to decrypt and transcribe it. According to both outlets, the operators did not break the encryption, reach a database or read stored user conversations.
FourWeekMBA reports that a footnote describes the figures as attempted extractions, not necessarily successful ones. It also reports that no success rate was disclosed.
Who OpenAI names, and how firmly
OpenAI wrote that it is unclear whether all operators came from a single actor. It attributes "a core cluster of the activity to individuals associated with Moonshot AI", in the words FourWeekMBA quotes from the post.
Moonshot AI has no quoted response in the post or in either outlet's account. The Next Web and FourWeekMBA both note that OpenAI is a party to the dispute and that the account is its own.
Caroline Zier, who leads strategic national security policy at OpenAI, told Bloomberg, in The Next Web's rendering: "Our concern is about violation of our terms of service, not open models or legitimate distillation."
What OpenAI changed
OpenAI said it banned the accounts involved, tightened sign-up checks and added protections for hidden reasoning. It also said it shared findings with the Frontier Model Forum and with government channels, according to The Next Web.
OpenAI did not say how many of the 16,000 requests returned usable reasoning text. It did not say which models were targeted or whether any Kimi release used the output. It has not said why disclosure took 64 days.
Earlier coverage of OpenAI on this site includes its AI math release norms advisory group and its $30 billion round at a $1.4 trillion pre-money valuation. A written response from Moonshot AI is the next fact that would change this story.
Sources
More in A.I.
- 01GPT-Synopsys: OpenAI Gets Paid Only When the Chips It Helps Design Beat the Customer's BaselineThe Sept. 30 deal pairs an OpenAI model with Synopsys' design software, with no price, no release date and no named customer.
- 02Ataraxos Beats Stratego's Top Player 15-1-4 After Training on 16 H100s for a WeekA Nature paper from MIT, Carnegie Mellon, NYU and Stanford puts the compute bill under $8,000, against an estimated $3 million to $4.5 million for DeepMind's DeepNash.
- 03Nine Mathematicians Advising OpenAI Ask AI Labs to Stop Testing Hard Problems on Models Nobody Else Can UseThe Advisory Group on Mathematics and AI published its rules on Sept. 29: release fast, fund human understanding, disclose prompts and costs.
- 04Qwen3.8-27B Ships Under Apache 2.0 and Fits in 17GB, but Spends 160 Million Tokens Where the Median Spends 43 MillionAlibaba's open-weight model scores 52 on Artificial Analysis's Intelligence Index. Its own benchmark figures are vendor-supplied, and users report slow runs.