TLDR
- OpenAI identified an organized campaign attempting to access concealed reasoning processes within its AI systems beginning in early July.
- The operation escalated dramatically, reaching 16,000 suspicious requests from more than 4,000 user accounts within a 48-hour period, with patterns detected across over 15,000 total users.
- The company confirmed that no encryption systems, internal databases, or archived user dialogues were compromised during the incident.
- Investigation revealed that a significant portion of the suspicious activity originated from individuals associated with Moonshot AI, the company behind the Kimi AI assistant.
- This revelation comes shortly after Anthropic leveled comparable allegations against both Moonshot AI and Alibaba.
[[LINK_START_0]]OpenAI[[LINK_END_0]] has disclosed that it identified and neutralized an organized campaign designed to extract proprietary reasoning data from its artificial intelligence models. The organization traced a substantial portion of this suspicious activity to individuals affiliated with Moonshot AI, a China-based developer responsible for creating the Kimi AI platform.
The company’s investigation revealed that suspicious activity began appearing in early July at relatively modest levels. However, the situation intensified dramatically on July 24 and 25, when OpenAI’s systems registered approximately 16,000 requests exhibiting remarkably similar characteristics, originating from more than 4,000 distinct user accounts.
Further analysis uncovered that the campaign extended beyond this initial group, with suspicious patterns appearing across an additional network of over 15,000 user accounts. OpenAI confirmed that it successfully terminated the entire operation by July 28.
Details of the Extraction Attempt
The technique employed in this incident is what OpenAI identifies as “adversarial distillation.” This process involves capturing a model’s outputs or internal reasoning processes and leveraging that information to develop or enhance a competing model without authorization.
Importantly, OpenAI clarified that the perpetrators did not compromise its encryption infrastructure, backend databases, or archived user interactions. Rather, they exploited a vulnerability that allowed concealed reasoning from one conversation thread to become visible within an entirely separate conversation.
This exploitation enabled unauthorized access to reasoning processes that OpenAI deliberately keeps hidden from end users. The company emphasized that such extraction techniques could enable competitors to replicate sophisticated AI capabilities while circumventing the substantial investments in development time and safety protocols.
OpenAI disseminated its investigative findings with peer organizations in the AI sector through the Frontier Model Forum. Additionally, the company coordinated with relevant government agencies to share this intelligence.
OpenAI’s Response Measures
Following the discovery of this coordinated activity, OpenAI implemented multiple countermeasures. The company’s actions included restricting access to or completely deactivating accounts identified as participating in the extraction attempts.
Additionally, OpenAI deployed enhanced safeguards designed to prevent malicious actors from establishing new accounts for similar purposes. The specific vulnerability that enabled this particular extraction method was patched and secured.
The organization also implemented sophisticated monitoring systems capable of identifying this type of adversarial activity as it occurs. In situations where the suspicious activity involved third-party platforms or services, OpenAI collaborated directly with those providers to locate and disable the associated accounts.
According to CNBC, Moonshot AI has not issued any public statement or response to requests for comment regarding these allegations.
Growing Concerns About Moonshot AI
These accusations represent the latest in a series of controversies surrounding Moonshot AI. Michael Kratsios, director of the White House Office of Science and Technology Policy, has publicly stated that Moonshot conducted extensive distillation operations targeting American AI models.
Kratsios has additionally alleged that Moonshot acquired restricted Nvidia processing chips to develop its Kimi K3 model. In a separate incident, security research organization Frontier Security reported that the Kimi K3 system successfully circumvented a cybersecurity evaluation framework developed by the U.K. government’s AI Safety Institute.
Moonshot AI has remained silent on these allegations as well.
These developments emerge just weeks after Anthropic publicly accused both Moonshot AI and Alibaba of utilizing its Claude model to train their proprietary systems without obtaining proper authorization.
OpenAI anticipates that similar extraction campaigns will continue to emerge as the AI industry evolves. The company warns that detecting such activities will become increasingly challenging as artificial intelligence models grow more sophisticated and capable.





