OpenAI Says a Moonshot-Linked Cluster Replayed Encrypted Reasoning Across Chats
Security / news
OpenAI Says a Moonshot-Linked Cluster Replayed Encrypted Reasoning Across Chats
The attempt did not crack encryption. It asked one conversation to decrypt hidden reasoning copied from another, and OpenAI says 16,000 requests landed in two days in July.

OpenAI says a coordinated campaign tried to extract the hidden reasoning of its models by copying encrypted reasoning out of one conversation and asking a model in another to decrypt and transcribe it. The company disclosed the operation on September 30, according to Hyper.ai's summary of the post, and attributes one cluster to individuals associated with Moonshot AI, the developer of Kimi.
We could not load OpenAI's own post, titled "Disrupting a coordinated model-distillation campaign", so every figure below comes from three outlets that quote it. Treat them as OpenAI's claims, not independent findings.
What OpenAI says happened
The activity began on July 1 at low volume, then spiked on July 24 and 25, per Wccftech. The spike was about 16,000 requests from more than 4,000 users. OpenAI later found related activity involving more than 15,000 users in total and says it fully disrupted the campaign by July 28.
| Date | Event |
|---|---|
| July 1 | Low-volume activity begins |
| July 24 and 25 | Spike of about 16,000 requests, 4,000+ users |
| July 28 | OpenAI says the campaign is fully disrupted |
| September 30 | Public disclosure |
- Users in July 24-25 spike4000 count
- Requests in July 24-25 spike16K count
- Users in the wider activity15K count
Source: OpenAI figures as relayed by Hyper.ai and Shattered.io, accessed 2026-10-05
The 4,000 and 15,000 user figures are floors ("more than"). Shattered.io notes the 16,000 are attempted extractions, not confirmed successes.
The method: no break-in, a confused deputy
OpenAI says the operators "did not crack encryption, breach databases, or directly access stored user conversations." The trick was to move an encrypted reasoning blob between sessions and ask the second session's model to read it back out. In effect, a request phrased as transcription was used to get hidden text shown to the requester.
OpenAI describes the goal as extracting reasoning "that would not normally appear in responses, for use in training, replicating, or improving other models." Hidden reasoning, not the visible answer, is the asset it says it is protecting.
Who OpenAI named, and who has not answered
Shattered.io reports that OpenAI is naming individuals associated with Moonshot AI, not necessarily the company's leadership, and could not confirm a single actor. As of that outlet's October 3 article, Moonshot had issued no public statement or denial.
Wccftech places the disclosure beside the debut of Moonshot's Kimi K3 and a claim by White House official Michael Kratsios that Moonshot had distilled from Anthropic's technology. Those are separate allegations about a different lab, and OpenAI's post does not, in the coverage we read, depend on them.
What OpenAI changed
Per Hyper.ai, OpenAI banned or restricted the accounts, tightened registration and infrastructure controls, upgraded detection on streamed output, and closed the paths that let encrypted reasoning be replayed across different users, workspaces and models. It shared findings with industry partners through the Frontier Model Forum and with government information-sharing channels.
Closing the cross-conversation replay path is the structural fix. The extra output checks are a patch on top.
What to watch
Watch for Moonshot's response and for whether other labs that ship encrypted reasoning report the same pattern. Our earlier piece on OpenAI agents found acting on Wikimedia projects shows the same company disclosing misuse after the fact, and Anthropic's handling of user data shows how quickly such disclosures turn into policy arguments.
Sources
More in Security
- 01Pwn2Own Ireland 2026 Day One: Seven of 20 Listed Entries Were Collisions, and OpenAI Codex Fell to Argument InjectionSamsung's Galaxy S26 was hit three times, Sonos and Philips Hue each twice or more, and a Google Pixel 10 attempt ran out of time. Vendors get 90 days before details go public.
- 02Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight ProductsAn unauthenticated request can read a file from the web root if the attacker already knows its exact path. Atlassian reports no exploitation and has released fixes for each product line.
- 03WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2The 9.2 rating describes a file include; code execution needs a theme folder starting with page- and a PHP setting, but probes began five hours after the patch.
- 04Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited ListBuilds that closed two exploited zero-days stay vulnerable to a SAML flaw that CISA added on October 4 with a three-day deadline.