OpenAI disrupts 16,000-request reasoning-extraction campaign, links core cluster to Moonshot AI
Verified· Sep 30, 2026Published Sep 30, 2026
OpenAI says it disrupted a July campaign that copied encrypted model reasoning between conversations to extract it, attributing the core cluster to individuals associated with Moonshot AI — figures represent attempted, not necessarily successful, extractions.
What happened
- OpenAI published a security post on September 30, 2026 saying it identified and disrupted a coordinated campaign designed to extract "protected reasoning" from its models — a practice OpenAI calls adversarial distillation: systematically using one model's outputs or reasoning to train, reproduce, or improve another model without authorization.
- The technique: operators copied encrypted reasoning traces from one conversation into another and asked the model to decrypt and transcribe them — reproducing hidden reasoning in visible form at scale, in violation of OpenAI's terms of service.
- Timeline: activity began July 1 at low volume; on July 24–25, high-volume spikes hit 16,000 requests using the extraction pattern from more than 4,000 users; further investigation found related prompt-pattern activity across more than 15,000 users, which OpenAI says it fully disrupted by July 28. OpenAI's footnote: these figures describe attempted, not necessarily successful, extractions.
- Attribution: OpenAI attributes "a core cluster" of the activity to individuals associated with Moonshot AI, the Chinese developer of Kimi — while stating it is unclear whether all operators originated from a single actor.
- OpenAI says the operators did not break its encryption, compromise a database, or gain direct access to stored user conversations, and that the technique is not a vulnerability unique to its models. It shared details with industry partners through the Frontier Model Forum.
- Context: on September 8, 2026, the NSA, CISA, and FBI issued a joint cybersecurity advisory stating Moonshot AI had conducted a widespread distillation campaign against US frontier AI companies since at least mid-2025 — including extracting Claude Fable 5 data to train Kimi-K3 and GPT-4o data to train Kimi-K2.
Why it matters
- OpenAI frames adversarial distillation as a safety and national-security risk: extracted reasoning can train rival models without preserving the original model's safeguards, accelerating capability transfer without the same safety investment — with concerns heightened as models gain dual-use capabilities.
- Response: OpenAI says it banned or restricted fraudulent accounts, strengthened signup and infrastructure controls, expanded monitoring, closed the pathway that allowed replaying someone else's encrypted reasoning, and shared findings through the Frontier Model Forum and government channels — while noting additional mitigation and investigation work is continuing.
Sources
- https://www.unite.ai/openai-disrupts-coordinated-model-reasoning-extraction-campaign/
- https://www.theregister.com/security/2026/09/30/irony-alert-openai-whines-that-chinese-model-stole-its-special-ip-that-it-stole-from-everybody-else/5300285
- https://www.citybiz.co/article/912019/openai-links-large-scale-reasoning-extraction-campaign-to-moonshot-ai/
- https://wccftech.com/moonshot-ai-of-kimi-k3-fame-tried-to-crack-openais-encrypted-reasoning-through-16000-requests-bolstering-trump-administrations-distillation-claims/
Sources
- ReportOpenAI Disrupts Coordinated Model Reasoning Extraction Campaign — Unite.AI
- ReportIrony alert: OpenAI complains Chinese model extracted its reasoning — The Register
- ReportOpenAI Links Large-Scale Reasoning Extraction Campaign to Moonshot AI — CityBiz
- ReportMoonshot AI tried to crack OpenAI's encrypted reasoning through 16,000 requests — Wccftech