How OpenAI Caught a 16,000-Request Bid to Copy Its AI Reasoning

Feature Image

On September 30, 2026, OpenAI said it had identified and shut down a coordinated campaign to pull the hidden “thinking” out of its AI models, and it pointed a finger at people linked to Moonshot AI, the Chinese developer of the Kimi family of models.[1][2] The disclosure is the first time OpenAI has publicly accused Moonshot of trying to copy its systems, and it lands in the middle of a widening dispute over how frontier models are trained.[4]

The company described the activity as “adversarial distillation,” the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model.[1] According to OpenAI, the operators never broke its encryption or reached stored user conversations; instead they manipulated model interactions to make hidden reasoning visible.[1][2]

What OpenAI says happened

OpenAI says the activity began quietly in the first week of July 2026.[1] It stayed at low volume until July 24 and 25, when the company recorded 16,000 requests from more than 4,000 users following the same extraction pattern.[1][3] Looking further, OpenAI identified related prompt-pattern activity across a cluster of more than 15,000 users and said it fully disrupted the campaign by July 28.[1][3]

The company notes in a footnote that those numbers describe attempted, not necessarily successful, extractions.[1]

  • Start: low-volume activity from July 1, 2026.[1]
  • Peak: 16,000 requests from over 4,000 users on July 24-25.[1]
  • Scope: related activity across more than 15,000 users.[1]
  • Disrupted: by July 28, 2026.[1]

The trick: replaying encrypted reasoning

Reasoning models do not just produce an answer; they first generate an internal record for working through a task. OpenAI calls this “protected reasoning,” and it can reveal information that the final answer withholds, which is exactly why a rival might want it.[1]

The operators copied encrypted reasoning from one conversation, then asked a model in a separate conversation to decrypt and transcribe that hidden content in plain text.[1][3] OpenAI called the method novel and stressed that it was not a database breach: “The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” the company wrote.[3]

“This activity is consistent with adversarial distillation: the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model.” — OpenAI[4]

Independent security researchers also reported related cross-model and conversation-compaction vulnerabilities through responsible disclosure, and OpenAI said it confirmed those attack paths were real.[1] As part of the fix, OpenAI closed a pathway that let someone who already held another user’s encrypted reasoning replay it and recover its contents, and added checks to detect and hold streamed output that might expose reasoning.[1][3]

Why labs and governments are worried

OpenAI argues the stakes go beyond one company’s intellectual property. Extracted reasoning could be used to train another model without carrying over the safeguards applied to the original model’s user-facing answers, and at scale it can move advanced capabilities to new players without the same investment in safety.[1] The company says the underlying weakness is not unique to its systems and shared details with industry partners through the Frontier Model Forum.[1][3]

The report also fits a broader pattern of accusations. OpenAI rival Anthropic said in September that several Chinese AI developers, including Moonshot AI and Alibaba, had secretly used its Claude model to help train their own systems.[2] US agencies have made similar charges, with an advisory naming six Chinese firms and the US models each one targeted, a move China rejected as unfounded.[4]

Not everyone accepts the framing. David Sacks, a former AI adviser in the Trump administration, has described such reports as a push to get the United States to ban rival open models, and Moonshot did not immediately respond to CNBC’s request for comment.[2][4] The company also faces scrutiny at home, where Chinese regulators are investigating DeepSeek and Moonshot.[4]

What it means for developers and buyers of AI

For builders, the episode is a reminder that model “thinking” is sensitive data, not just a debug view.[1] Systems that support portable or replayable reasoning artifacts may carry the same class of risk, OpenAI warned, and partner-hosted deployments need the same protections as first-party services.[1]

OpenAI says its response combined account enforcement, tighter sign-up and infrastructure controls, expanded network monitoring, and coordination with third-party providers where the activity moved through their services.[1][2][3] Cybersecurity researchers have long described a black-and-gray market for bulk accounts used to flood models with prompts, which is the supply chain these campaigns depend on.[3]

OpenAI acknowledged that its attribution is not airtight: it said it was unclear whether every operator came from a single actor, though it attributed a core cluster to individuals associated with Moonshot.[1][2] CyberScoop noted that the blog post did not cite technical evidence for that attribution.[3] Moonshot’s Kimi models remain popular precisely because they offer strong performance at low cost, which keeps the distillation debate politically charged.[3]

OpenAI said the work is not finished and that it will keep improving tool defenses, classifier coverage, and model refusals.[1] For teams evaluating AI vendors, the practical question is increasingly contractual and architectural: who can replay your reasoning, where does it travel, and what safeguards follow it.

Sources

  1. Disrupting a coordinated model-distillation campaign — OpenAI, 30 September 2026
  2. OpenAI links China’s Moonshot AI to extraction attempt — CNBC, 1 October 2026
  3. OpenAI reveals ‘novel’ encryption bypass used in distillation attack — CyberScoop, 1 October 2026
  4. OpenAI says Moonshot-linked users tried to extract its AI reasoning — The Next Web, 1 October 2026

Comments

Login to comment