The news
OpenAI said on September 30, 2026, that it had disrupted a coordinated model distillation campaign aimed at extracting its models' hidden reasoning, and attributed a core cluster of the activity to individuals associated with Moonshot AI, the Beijing-based developer of Kimi.
Distillation means training one model on the outputs of another. OpenAI described this case as adversarial distillation: the systematic, unauthorized use of a model's outputs or reasoning to train, reproduce or improve a different model. Reasoning models work through intermediate steps before they answer, and OpenAI treats those hidden steps as protected.
According to OpenAI, the activity began at low volume on July 1, 2026. It spiked on July 24 and 25, when the company counted 16,000 attempted requests using an extraction pattern from more than 4,000 users. Further investigation found related prompt-pattern activity across more than 15,000 users, and OpenAI said the campaign was fully disrupted by July 28.
OpenAI said the operators did not break its encryption, compromise a database or gain access to stored user conversations. Instead, they manipulated model interactions so that protected reasoning came back in a form they could read. In one technique the company described, operators copied encrypted reasoning from one conversation and asked a model in a separate conversation to decrypt and transcribe it.
The company hedged its attribution. OpenAI said it was unclear whether all of the operators it observed came from a single actor, and The Hacker News noted that OpenAI did not publish technical evidence for the Moonshot link. Moonshot had not responded to OpenAI's post, Decrypt reported.
OpenAI said it banned or restricted fraudulent accounts, strengthened signup and infrastructure controls and expanded monitoring for related networks. It closed a pathway that let someone holding another user's encrypted reasoning replay it and recover its contents, and it shared its findings through the Frontier Model Forum and government information-sharing channels so other frontier developers could look for similar activity.
The numbers
- Attempted extraction requests, July 24-25
- 16,000
- Users behind those requests
- More than 4,000
- Users with related prompt-pattern activity
- More than 15,000
- Campaign window
- July 1 to July 28, 2026
Why CEOs should care
For companies that build or license frontier models, this is a reminder that the product itself is the attack surface. OpenAI warned that extracted reasoning could train another model without the safeguards applied to the original, and that distillation at scale can transfer advanced capabilities without the same investment in safety. Buyers should ask their model vendors how they detect coordinated extraction, what they log and how quickly they act on it.
For CISOs, the method matters more than the attribution. Nothing was hacked in the traditional sense: the operators used thousands of accounts and patterned prompts to coax protected material out of normal product behavior. Any company that exposes a fine-tuned model, an AI feature or a data API through accounts faces the same pattern. Questions to ask: can we spot one actor spread across many accounts, do our terms ban using outputs to train competing models, and can we enforce that in practice?
For boards and procurement teams, the accusation adds to a growing list aimed at Chinese AI labs. Companies running Kimi or other Chinese open-weight models should map where those models sit in their stack and track whether accusations like this one turn into government restrictions, since that could force a switch on short notice.
The bigger picture
Distillation fights are becoming a standing feature of the model race. Decrypt recounted earlier accusations against DeepSeek in January 2025 and Anthropic's claim in February that Chinese labs used about 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude. Anthropic has separately accused Moonshot of relaying customer requests to Claude instead of processing them with Kimi, The Hacker News reported. Bloomberg reported that this is the first time OpenAI has accused Moonshot, according to The Next Web.
The politics are contested. The Next Web reported that a U.S. government advisory in September named six Chinese firms and the U.S. models each targeted, and that China rejected it as unfounded. David Sacks, the former White House AI czar, has called such reports a push to ban rival open models. OpenAI's Caroline Zier told Bloomberg the company's concern is terms-of-service violations, "not open models or legitimate distillation."
What’s next
Watch for a response from Moonshot, which Decrypt reported is targeting a $3 billion initial public offering in Hong Kong at a $50 billion valuation, and for other Frontier Model Forum members to report whether they found similar activity. Also watch whether U.S. agencies act on the findings OpenAI shared through government channels, and whether model providers change how they protect encrypted reasoning, a design that researchers from MATS Research, ELLIS Institute Tübingen and Synk flagged in an August 2026 study cited by The Hacker News.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








