Key facts
- OpenAI claims to have shut down a coordinated effort to copy its AI models' hidden reasoning.
- A core cluster of the activity is attributed to individuals associated with Moonshot AI, maker of the Kimi chatbot.
- The campaign began July 1 and involved 16,000 extraction requests from over 4,000 users on July 24-25 alone.
- OpenAI states the operators did not break encryption or gain direct access to user conversations.
- The goal was to reproduce protected reasoning in visible forms to train other models without original safeguards.
- OpenAI fully disrupted the activity by July 28.
OpenAI has announced it has disrupted a coordinated campaign by individuals associated with China's Moonshot AI to extract and copy the hidden reasoning processes of its AI models. The campaign, which began on July 1, aimed to replicate the AI's internal thought processes before it generates an answer, a method OpenAI calls adversarial distillation.
According to OpenAI, the operators did not breach encryption or access user data directly. Instead, they manipulated model interactions to reproduce the protected reasoning in a visible format. On July 24 and 25 alone, OpenAI logged 16,000 extraction requests from over 4,000 users, part of a broader cluster involving more than 15,000 users. OpenAI stated it had fully disrupted this activity by July 28 and has since closed the specific pathway exploited.
OpenAI noted that while it attributes a core cluster of the activity to individuals linked with Moonshot AI, it remains unclear if all operators originated from a single actor. The company views this unauthorized use of model outputs to train other models as a violation of its terms of service. Such practices can allow smaller models to achieve better results without extensive training, but done without authorization, it is considered adversarial distillation.
This incident is part of a broader trend of AI companies accusing entities, particularly those in China, of engaging in large-scale model extraction and distillation. OpenAI itself faced similar accusations in January 2025 regarding DeepSeek, and Anthropic has also accused Chinese labs of fraudulent account usage. The White House has previously warned about such industrial-scale distillation campaigns by foreign entities, primarily from China.

