OpenAI Says People Tied to Moonshot AI Sought Its Hidden Reasoning
OpenAI says it disrupted a coordinated campaign to extract the encrypted internal reasoning of its AI models and attributes a core cluster of the activity to individuals associated with Moonshot AI, the Chinese developer of the Kimi chatbot. The effort peaked in late July with 16,000 extraction requests in two days, according to the company. Moonshot has not responded.
OpenAI says it has shut down a coordinated effort to copy the hidden reasoning behind its AI models' answers, and it attributes a core cluster of that activity to individuals associated with Moonshot AI, the Chinese startup behind the Kimi chatbot. According to OpenAI, the campaign began on July 1 and was fully disrupted by July 28.
The scale was substantial. OpenAI says it logged 16,000 extraction requests from more than 4,000 users on July 24 and 25 alone, part of a wider cluster involving over 15,000 users. The company emphasized that the operators did not break its encryption, compromise a database, or obtain direct access to stored user conversations, but instead manipulated model interactions so that protected reasoning could be reproduced in visible form at scale in violation of its terms of service.
The target was not the final answers but the work behind them. Modern AI models reason through problems step by step in an internal scratchpad before delivering a clean response, and OpenAI keeps that scratchpad encrypted because it can reveal information the final answer omits. One method described by the company involved copying encrypted reasoning out of one conversation and asking a model to decode it in another; OpenAI says it has since closed a pathway that let someone with another user's encrypted reasoning replay it to recover its contents.
OpenAI frames the goal as distillation—training a smaller model on the outputs of a stronger one to improve results without heavy training costs. When done without authorization, it calls this adversarial distillation, defined as the systematic and unauthorized use of one model's outputs or reasoning to train, reproduce or improve another model. Because AI outputs are not copyrightable, companies rely on terms-of-service prohibitions and safeguards rather than copyright claims to prevent competitors from using them.
The accusation follows a pattern of similar disputes. In January 2025, OpenAI said it was reviewing signs that DeepSeek may have distilled its models, and Anthropic followed in February by accusing Chinese labs of using roughly 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude. By April, the White House said foreign entities, primarily in China, were running industrial-scale distillation campaigns; a week later Elon Musk acknowledged in court that xAI used distillation on OpenAI models to train Grok. In June, Anthropic asked Congress for penalties on large-scale model extraction, and in August researchers showed that OpenAI, Anthropic and Google each protected reasoning with a single provider-wide encryption key, prompting server-side patches from all three.
OpenAI's post does not link the campaign to Kimi's underlying model, and the company acknowledged that it is unclear whether all operators observed during the period came from a single actor, while still attributing a core cluster to individuals associated with Moonshot AI. Moonshot has not responded to OpenAI's post. The company is targeting a $3 billion IPO in Hong Kong at a $50 billion valuation.
TopicsOpenAI · Moonshot AI · Kimi · DeepSeek · Anthropic · Google · Elon Musk · xAI
Source: decrypt.co
Written by Paparazzi with AI. Not financial advice.

