OpenAI said it shut down a coordinated effort to copy how its AI models think and traced a core cluster of the activity to individuals associated with Moonshot AI, the Chinese startup behind the Kimi chatbot.

According to OpenAI, the campaign began on July 1. On July 24 and 25 alone, the company logged 16,000 extraction requests from more than 4,000 users, part of a broader cluster involving over 15,000 users. OpenAI said it fully disrupted the activity by July 28.
The target was the reasoning behind the answer
The company said the campaign was not focused on model outputs alone, but on the internal work that happens before a response is shown. Modern AI systems reason through a problem step by step in an internal scratchpad and then present a polished answer to the user. OpenAI said that scratchpad is encrypted, and extracting it can expose information that does not appear in the final response.
OpenAI wrote: “The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations. Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.”
One method, the company said, involved copying encrypted reasoning from one conversation and then asking a model to decode it in another conversation.
OpenAI stopped short of directly tying the campaign to K3
OpenAI’s post did not connect the campaign to K3, though it said the picture was not fully settled. “It is unclear whether all operators we observed during the relevant time period originated from a single actor. However, we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi,” the company said.
OpenAI also said it has closed a pathway that previously allowed someone who already possessed another user’s encrypted reasoning to replay it and recover its contents.
OpenAI describes the conduct as adversarial distillation
The report said there is a clear incentive to obtain this material. Distillation allows a developer to train a new model on the outputs of a stronger one, improving the performance of smaller models without the same training burden.
When this is done without authorization, OpenAI calls it adversarial distillation, defining it as “the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model.”
The article also placed the issue within a broader set of disputes around AI companies. The most visible example remains the illegal or unauthorized use of copyrighted material in model training. Distillation is different in that it does not reach that far, the report said. Because AI outputs are not copyrightable, companies rely on terms of service restrictions and technical safeguards to stop competitors from reusing them.
A charge that has surfaced before
OpenAI has raised similar concerns before. In January 2025, it said it was reviewing signs that DeepSeek may have distilled its models while Washington was weighing national security risks.
Anthropic followed in February, accusing Chinese labs of using about 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude. Critics online responded that Claude itself had been trained on the open internet.
By April, the White House was saying that foreign entities, primarily in China, were conducting industrial-scale distillation campaigns. A week later, Elon Musk acknowledged in court that xAI used distillation on OpenAI models to train Grok.
In June, Anthropic took the issue to Congress and asked for penalties targeting large-scale model extraction.
In August, researchers showed that OpenAI, Anthropic, and Google each protected reasoning with a single provider-wide encryption key, and that attackers could coax models into revealing hidden thoughts in plain text. All three companies deployed server-side patches after disclosure, though session logs shared earlier remain decodable.
Moonshot has not responded
Moonshot had not responded to OpenAI’s post at the time of publication. The report added that the company is targeting a $3 billion IPO in Hong Kong at a $50 billion valuation.

