Key Points
- OpenAI identified an organized campaign beginning in early July aimed at extracting concealed reasoning processes from its artificial intelligence models.
- The operation escalated dramatically over two days, generating 16,000 suspicious requests from more than 4,000 individual users.
- The company confirms that no encryption systems, databases, or user conversation archives were compromised during the incident.
- Investigation revealed that a significant portion of the coordinated activity originated from individuals associated with Moonshot AI, the organization behind the Kimi AI platform.
- This revelation comes shortly after Anthropic leveled comparable allegations against both Moonshot AI and Alibaba in recent weeks.
[[LINK_START_0]]OpenAI[[LINK_END_0]] has revealed that it identified and terminated a systematic operation designed to extract concealed reasoning capabilities from its artificial intelligence systems. The organization traced a significant concentration of this activity to individuals affiliated with Moonshot AI, a China-based enterprise responsible for developing the Kimi AI platform.
The company reports that suspicious activity began appearing at minimal levels during the first week of July. The situation escalated dramatically on July 24 and 25, when OpenAI’s systems registered 16,000 coordinated requests originating from over 4,000 distinct user accounts, all exhibiting remarkably similar behavioral patterns.
Subsequent investigation uncovered that the operation extended far beyond the initial detection scope, ultimately implicating a network exceeding 15,000 user accounts. OpenAI confirms it successfully neutralized the entire campaign by July 28.
Technical Details of the Operation
OpenAI characterizes the technique employed as “adversarial distillation.” This process involves extracting a model’s outputs or internal reasoning processes and leveraging them to develop or enhance a competing model without authorization.
The organization emphasizes that the perpetrators did not compromise its encryption infrastructure, database systems, or archived user interactions. Instead, they exploited a vulnerability that enabled hidden reasoning from one conversation thread to become accessible within an entirely separate conversation.
This vulnerability allowed the operators to access reasoning processes that OpenAI intentionally conceals from end users. The company warns that such extraction techniques could enable competitors to replicate sophisticated AI capabilities while circumventing the substantial investment in research, development, and safety protocols.
OpenAI disseminated its investigation results to fellow AI developers through the Frontier Model Forum collaborative network. The company additionally briefed relevant government authorities about the incident.
OpenAI’s Response Measures
Following discovery of the coordinated operation, OpenAI implemented multiple countermeasures. The company restricted access to or completely terminated accounts identified as participating in the suspicious request patterns.
Additionally, OpenAI deployed new protective mechanisms designed to prevent actors from establishing fresh accounts for similar exploitation purposes. The specific vulnerability that permitted this particular extraction method has been permanently closed.
The organization has implemented enhanced monitoring systems capable of identifying comparable activity patterns in real time. In instances where the operation utilized third-party services, OpenAI collaborated with those platform providers to locate and disable the associated accounts.
According to CNBC, Moonshot AI has not issued any response to media requests for comment on these allegations.
Escalating Concerns Surrounding Moonshot
These accusations represent the latest in a series of controversies involving Moonshot AI. Michael Kratsios, director of the White House Office of Science and Technology Policy, has publicly alleged that Moonshot conducted extensive distillation operations targeting American AI models.
Kratsios has further claimed that Moonshot acquired restricted Nvidia processing chips to construct its Kimi K3 model. Additionally, security research organization Frontier Security reports that Kimi K3 successfully breached a cybersecurity evaluation framework developed by the United Kingdom government’s AI Safety Institute.
Moonshot has remained silent regarding these additional allegations as well.
These developments emerge just weeks after Anthropic publicly accused both Moonshot AI and Alibaba of utilizing its Claude model to assist in training their proprietary systems without obtaining proper authorization.
OpenAI anticipates that similar exploitation attempts will continue and likely intensify going forward. The company projects that such operations will become increasingly sophisticated and challenging to identify as artificial intelligence technologies continue advancing.


