AI Affairs, home

Friday 2 October 2026

News

OpenAI links Moonshot AI individuals to model-distillation campaign

OpenAI says the activity peaked at 16,000 requests across two July days and involved prompts seeking hidden reasoning from its GPT models.

OpenAI co-founder and CEO Sam Altman speaking onstage at TechCrunch Disrupt San Francisco 2019.
Photo: TechCrunch, CC BY 2.0, via Flickr (cropped)

OpenAI on 30 September accused individuals associated with Moonshot AI of playing a significant role in a coordinated campaign to extract protected reasoning from its GPT models, Bloomberg News reported. The allegation names the developer of Kimi in a dispute over attempts to obtain information that OpenAI keeps hidden from users.

Key points

  • OpenAI attributes a core cluster of the activity to individuals associated with Moonshot AI, rather than every account involved.
  • OpenAI says the campaign peaked at 16,000 requests later in July.
  • The prompts sought a readable version of reasoning concealed from users, OpenAI says.
  • OpenAI says it fully disrupted the campaign by 28 July.

The July requests targeted hidden reasoning

OpenAI said it first observed the activity on 1 July at low volume, before a spike later in the month: 16,000 requests matching the extraction pattern came from more than 4,000 users, Wccftech reported. OpenAI put the wider cluster of users involved in that prompt pattern at more than 15,000, according to the same publication.

The method took encrypted reasoning from one conversation and put it into another with a request for the model to decrypt and transcribe the concealed content, OpenAI said. That matters because OpenAI has been limiting what users can see of its models’ reasoning, giving them answers rather than the full path to those answers.

OpenAI said the method revealed a version of the reasoning readable to its internal servers, but did not decrypt it. The company also said the campaign did not breach its encryption or give the operators direct access to stored conversations.

OpenAI names individuals associated with Moonshot AI

OpenAI’s attribution is narrower than blaming every request on Moonshot AI. The company said individuals associated with the developer of Kimi were behind a core cluster, while it could not assign all the operators to one actor.

The allegation arrives amid other accusations against Chinese AI developers over distillation, a practice in which outputs from one model are used to train another. An earlier AI Affairs report covered Kimi K3’s arrival on Amazon Bedrock and a possible $20m revenue licence.

Representatives for Moonshot did not immediately respond to requests for comment, Bloomberg News reported. China’s government has rejected earlier distillation accusations from Silicon Valley companies and the Trump administration.

Caroline Zier draws a line at OpenAI’s terms

“Our concern is about violation of our terms of service, not open models or legitimate distillation,” Caroline Zier, OpenAI’s lead for strategic national security policy initiatives, told Bloomberg News. She said OpenAI shares its findings with other developers and relevant government partners and will invest in stronger protections.

OpenAI, Anthropic and Google have been coordinating on ways to counter what they call adversarial distillation, including activity by firms from China. OpenAI said it fully disrupted this campaign by 28 July, Wccftech reported.

Topics: Copyright, Foundation models, Safety