In brief
- OpenAI says a campaign that began July 1 sent 16,000 extraction requests from more than 4,000 users on July 24-25 alone, within a cluster of over 15,000 users.
- OpenAI attributes a core cluster of the activity to individuals associated with Moonshot AI, maker of Kimi, and says it is unclear whether all operators came from a single actor.
- The target was the hidden "reasoning" OpenAI's models generate before answering, which OpenAI says could train another model without the original safeguards.
OpenAI claims to have shut down a coordinated effort to copy the way its AI models think, and it traces a core cluster of that activity to people associated with Moonshot AI, the Chinese startup behind the Kimi chatbot.
The campaign began on July 1, according to OpenAI. On July 24 and 25 alone, it logged 16,000 extraction requests from more than 4,000 users, part of a wider cluster of over 15,000 users. OpenAI says it fully disrupted the activity by July 28.

The target wasn't the answers, but the work behind them.
Modern AI models "reason" before they reply—they work through a problem step by step in an internal scratchpad, then show you a clean result. OpenAI keeps that scratchpad encrypted, and says pulling it out can reveal information the final answer leaves out.
“The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” OpenAI said. “Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.”
One method involved copying encrypted reasoning out of one conversation and asking a model to decode it in another.
OpenAI's post doesn't connect the campaign to K3, but it leaves space for reasonable doubt. “It is unclear whether all operators we observed during the relevant time period originated from a single actor. However, we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi,” OpenAI said.
OpenAI has since closed a pathway that let someone who already had another user's encrypted reasoning replay it to recover its contents.
Why would anyone want it? Because distillation—training a new AI on the outputs of a stronger one—leads to better results from smaller models without heavy training.
Done without authorization, OpenAI calls it adversarial distillation: "the systematic and unauthorized use of one model's outputs or reasoning to help train, reproduce, or improve another model."
This is just one of the many scandals involving AI companies. The most obvious and popular one is the illegal or unauthorized use of copyrighted data to train models. Distillation doesn’t go this far. AI outputs are not copyrightable so companies include prohibitions and safeguards in their terms of service to prevent competitors from using those outputs.
A familiar accusation
OpenAI has been here before. In January 2025, it said it was reviewing signs that DeepSeek may have distilled its models, as Washington weighed national security risks.
Anthropic followed in February, accusing Chinese labs of using about 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude. Online critics shot back that Claude itself was trained on the open internet.
By April, the White House was saying foreign entities, primarily in China, were running industrial-scale distillation campaigns. A week later, Elon Musk acknowledged in court that xAI used distillation on OpenAI models to train Grok.
In June, Anthropic took the fight to Congress, asking for penalties for large-scale model extraction.
In August, researchers showed that OpenAI, Anthropic and Google each protected reasoning with a single provider-wide encryption key, and that attackers could coax models into spitting out the hidden thoughts in plain text. All three companies deployed server-side patches after disclosure, though session logs shared earlier remain decodable.
Moonshot hasn't responded to OpenAI's post. It’s targeting a $3 billion IPO in Hong Kong at a $50 billion valuation.

