OpenAI says it blocked effort to extract hidden AI reasoning, ties core activity cluster to Moonshot-linked individuals

OpenAI says it blocked effort to extract hidden AI reasoning, ties core activity cluster to Moonshot-linked individuals

N
News Editor
2026-10-01 19:46:03
OpenAI said it disrupted a coordinated campaign aimed at reproducing the hidden reasoning of its AI models and attributed a core cluster of that activity to individuals associated with Moonshot AI, the Chinese startup behind the Kimi chatbot. According to the company, the effort began on July 1, and on July 24 and 25 alone it logged 16,000 extraction requests from more than 4,000 users as part of a wider cluster involving over 15,000 users. OpenAI said it had fully shut down the activity by July 28. The company stressed that the operators did not break encryption, access databases, or directly retrieve stored user conversations. Instead, it said they manipulated model interactions so protected reasoning could be reproduced in requester-visible forms at scale, in violation of its terms of service. OpenAI said one tactic involved copying encrypted reasoning from one conversation and asking a model in another conversation to decode it. The company framed the conduct as unauthorized or adversarial distillation, a practice in which outputs or reasoning from a stronger model are used to help train or improve another model. Moonshot had not responded to OpenAI’s post at the time of publication.

OpenAI said it shut down a coordinated effort to copy how its AI models think and traced a core cluster of the activity to individuals associated with Moonshot AI, the Chinese startup behind the Kimi chatbot.

OpenAI says it blocked effort to extract hidden AI reasoning, ties core activity cluster to Moonshot-linked individuals

According to OpenAI, the campaign began on July 1. On July 24 and 25 alone, the company logged 16,000 extraction requests from more than 4,000 users, part of a broader cluster involving over 15,000 users. OpenAI said it fully disrupted the activity by July 28.

The target was the reasoning behind the answer

The company said the campaign was not focused on model outputs alone, but on the internal work that happens before a response is shown. Modern AI systems reason through a problem step by step in an internal scratchpad and then present a polished answer to the user. OpenAI said that scratchpad is encrypted, and extracting it can expose information that does not appear in the final response.

OpenAI wrote: “The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations. Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.”

One method, the company said, involved copying encrypted reasoning from one conversation and then asking a model to decode it in another conversation.

OpenAI stopped short of directly tying the campaign to K3

OpenAI’s post did not connect the campaign to K3, though it said the picture was not fully settled. “It is unclear whether all operators we observed during the relevant time period originated from a single actor. However, we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi,” the company said.

OpenAI also said it has closed a pathway that previously allowed someone who already possessed another user’s encrypted reasoning to replay it and recover its contents.

OpenAI describes the conduct as adversarial distillation

The report said there is a clear incentive to obtain this material. Distillation allows a developer to train a new model on the outputs of a stronger one, improving the performance of smaller models without the same training burden.

When this is done without authorization, OpenAI calls it adversarial distillation, defining it as “the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model.”

The article also placed the issue within a broader set of disputes around AI companies. The most visible example remains the illegal or unauthorized use of copyrighted material in model training. Distillation is different in that it does not reach that far, the report said. Because AI outputs are not copyrightable, companies rely on terms of service restrictions and technical safeguards to stop competitors from reusing them.

A charge that has surfaced before

OpenAI has raised similar concerns before. In January 2025, it said it was reviewing signs that DeepSeek may have distilled its models while Washington was weighing national security risks.

Anthropic followed in February, accusing Chinese labs of using about 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude. Critics online responded that Claude itself had been trained on the open internet.

By April, the White House was saying that foreign entities, primarily in China, were conducting industrial-scale distillation campaigns. A week later, Elon Musk acknowledged in court that xAI used distillation on OpenAI models to train Grok.

In June, Anthropic took the issue to Congress and asked for penalties targeting large-scale model extraction.

In August, researchers showed that OpenAI, Anthropic, and Google each protected reasoning with a single provider-wide encryption key, and that attackers could coax models into revealing hidden thoughts in plain text. All three companies deployed server-side patches after disclosure, though session logs shared earlier remain decodable.

Moonshot has not responded

Moonshot had not responded to OpenAI’s post at the time of publication. The report added that the company is targeting a $3 billion IPO in Hong Kong at a $50 billion valuation.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.