OpenAI Ties Moonshot AI to a July Campaign That Replayed Encrypted Reasoning, Offers No Evidence Publicly
A.I. / news
OpenAI Ties Moonshot AI to a July Campaign That Replayed Encrypted Reasoning, Offers No Evidence Publicly
OpenAI says 16,000 requests from more than 4,000 accounts tried to recover hidden model reasoning. Its attribution to Moonshot rests on its own assertion.

OpenAI said on Sept. 30 that a core cluster of the operators behind a July distillation campaign are associated with Moonshot AI, the Chinese developer of the Kimi models. The company said it "fully disrupted" the activity on July 28.
The disclosure came in a blog post titled "Disrupting a coordinated model-distillation campaign". As of Friday, Moonshot had not been quoted in any of the coverage reviewed. CyberScoop said it had reached out to the company for comment.
What OpenAI says happened between July 1 and July 28
OpenAI said it saw low-level activity consistent with adversarial distillation from early July. Distillation means training one model on another model's outputs.
| Date | Event, per OpenAI |
|---|---|
| July 1 | First activity consistent with distillation |
| July 24 and 25 | 16,000 requests from more than 4,000 users |
| July 28 | More than 15,000 users in the cluster; campaign disrupted |
| Sept. 30 | Public disclosure |
The gap between disruption and disclosure is 64 days. OpenAI did not explain it in the material quoted by the outlets reviewed.
How the encrypted reasoning was replayed
OpenAI said: "We saw operators attempt to extract protected reasoning in novel ways, including by copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe the hidden reasoning content."
The Register reported that OpenAI "closed a pathway that allowed someone who already possessed another user's encrypted reasoning to replay it and recover its contents." OpenAI also said the operators "did not break our encryption, compromise a database, or gain direct access to stored user conversations."
The method used ordinary API calls at scale, which is why the count of requests and accounts is the measure OpenAI leads with.

The attribution to Moonshot is OpenAI's alone
OpenAI said it strongly believes a core cluster of operators are associated with Moonshot AI. It also said it was unsure whether all the activity came from a single actor.
CyberScoop reported that the post contained no technical evidence for the attribution. No account identifiers, request samples or network indicators were published. No second organisation has confirmed the link in the sources reviewed.
OpenAI declined to say which technical weaknesses were exploited beyond the replay pathway, and did not say whether law enforcement was involved, BankInfoSecurity reported.
Why OpenAI says hidden reasoning matters
OpenAI's argument is about safety as well as competition. It said: "Extracted reasoning could be used to train another model without preserving the safeguards applied to the original model's user-facing outputs."
The company passed its findings to other AI companies through the Frontier Model Forum and to government information-sharing programs. CyberScoop reported that outside researchers had reported a similar vulnerability in August, after OpenAI's July disruption.
The case lands as OpenAI faces its own scrutiny, including an FTC investigation of consumer risks and questions about what its chip-design deal with Synopsys covers. OpenAI has not said whether it will pursue action against Moonshot or the accounts involved.
Sources
More in A.I.
- 01Qwen3.8-27B Ships Under Apache 2.0 and Fits in 17GB, but Spends 160 Million Tokens Where the Median Spends 43 MillionAlibaba's open-weight model scores 52 on Artificial Analysis's Intelligence Index. Its own benchmark figures are vendor-supplied, and users report slow runs.
- 02Gemini 4 Argon Leads 13 of 18 Benchmarks Google Chose, but Only Cyber Defenders Can Use ItGoogle priced the model at $2 and $10 per million tokens and gave access first to its Fairwind Program, with a guardrail-free version for trusted defenders.
- 03Amazon Releases Strands Decider 2B, an Apache 2.0 Decision Model Built on Qwen3.5-2BAWS's Strands Labs scores 72.3 percent on JevBench at a 106 ms median on an RTX 3090. TypeSafe's CEO calls the current crop of rivals less serious than his own team.
- 04OpenAI and Synopsys Sign Chip-Design Model Deal With No Customers or Benchmarks NamedGPT-Synopsys will run Synopsys EDA tools on OpenAI-hosted infrastructure under a revenue-sharing agreement. The Sept. 30 announcement gives no dollar figure and no ship date.