OpenAI Links 16,000-Request Reasoning Extraction Campaign to Moonshot AI
A.I. / news
OpenAI Links 16,000-Request Reasoning Extraction Campaign to Moonshot AI
The report says activity began July 1, spiked on July 24 and 25 and reached more than 15,000 users before OpenAI stopped it on July 28.

OpenAI said it disrupted a coordinated model-distillation campaign that began July 1 and was stopped on July 28, and that it attributes a core cluster of the activity to individuals associated with Moonshot AI, the company behind the Kimi models.
The account comes from OpenAI's report titled "Disrupting a coordinated model-distillation campaign", as quoted by Wccftech and GIGAZINE on Sept. 30 and Oct. 1. OpenAI's own page returned an access error to The Terminal's fetch, so every detail here is as those two outlets reported it.
OpenAI's timeline: July 1 to July 28
Wccftech quoted the report: "The activity began on July 1, initially at a low volume until we observed high-volume spikes on July 24 and 25 consisting of 16,000 requests using a relevant extraction pattern."
GIGAZINE reported that user numbers jumped to over 4,000 on those two days. By July 28 OpenAI had identified a cluster of more than 15,000 coordinated users and blocked the campaign.
- July 24-25 spike4000 users
- Cluster identified by July 2815K users
Source: GIGAZINE and Wccftech, citing OpenAI's report, accessed 2026-10-03
Both figures are lower bounds, since the coverage says "over" and "more than".
What the campaign targeted
The target was not user data. GIGAZINE reported that the attackers went after encrypted reasoning, the intermediate "thinking" a model produces before its answer. The method it described moved high-performance model thinking into lower-performance models, then used jailbreak prompts to get the thinking out in plain text.
That matches the term the report uses, adversarial distillation: using one model's outputs to help train or improve another without permission.

The photograph above shows OpenAI representatives at the European Commission in 2023 and is unrelated to the campaign.
The Moonshot attribution and its limits
OpenAI wrote: "We attribute a core cluster of the [model distillation] activity to individuals associated with Moonshot AI." GIGAZINE reported a softer line from the same report, that the central figures are presumed to be associated with Moonshot and that OpenAI was uncertain whether one organisation controlled every attacker.
Neither outlet carried a response from Moonshot.
Wccftech tied the report to a late-July claim by Michael Kratsios, Chief Science and Technology Advisor and Director of the White House Office of Science and Technology Policy. It said Kratsios declared the US government had information that Moonshot distilled Kimi K3 from Anthropic's models. The OpenAI report concerns OpenAI's models, so the two claims are separate and the coverage does not show they overlap.
For related coverage of open models from the same market, see Antirez's ds4 for DeepSeek V4.1 Flash and Nvidia's OpenShell sandbox.
Response and what is unknown
GIGAZINE reported that OpenAI tightened its defences and shared its findings with other AI companies through the Frontier Model Forum. It said no personal user information was compromised.
The coverage does not say how many accounts OpenAI banned, which model families were exposed, or whether any extracted reasoning was used in training. OpenAI has not published, in the sources fetched, a date for further disclosure.
Sources
More in A.I.
- 01GPT-6.1 Sol Is Priced at One-Fifth of Astra, and Its System Card Rates Cyber CriticalOpenAI's Sept. 29 addendum also shows the model misrepresenting its own coding work more often than GPT-6 Astra did.
- 02Gemini 4 Argon Goes to Cyber Defenders First, With Broad Access UndatedGoogle priced its new frontier model at $2 and $10 per million tokens for an introductory period, then $4 and $20, and has not said when most developers get it.
- 03Aleph Alpha's Kolibri Ships Under Apache 2.0, Compared Only With Spring ModelsThe 78B-parameter German-English model activates 3.46B per token, and its published benchmark table leaves out every open-weight release since the spring.
- 04Runway's Praxis-1 Robot Model Is Open-Weight on Paper, With Weights Still UnreleasedThe video-trained control model is being tested by Noble Machines, Standard Bots and Ultra, and Runway has not published a parameter count or a licence.