OpenAI confirmed it disrupted a coordinated campaign that tried to extract protected reasoning from its AI models, with a core cluster of the activity linked to individuals associated with Moonshot AI, the Chinese company behind the Kimi AI models.
According to OpenAI, the campaign began on July 1, 2026, and intensified later that month, with 16,000 requests recorded across more than 4,000 users on July 24 and 25. The company said it identified related activity involving more than 15,000 users and had fully disrupted the campaign by July 28.
OpenAI described the activity as adversarial distillation, a practice in which outputs or reasoning from one AI model are systematically collected to help train, reproduce, or improve another model. The company stressed that the figures refer to attempted extractions and do not establish how much protected reasoning was successfully obtained.
OpenAI said the operators did not break its encryption, access a database, or directly obtain stored user conversations. Instead, they manipulated interactions between models to make protected reasoning visible to the requester.
One technique involved copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe the hidden content. OpenAI said independent security researchers also reported related weaknesses involving cross-model interactions and conversation compaction. The company investigated those findings and confirmed that the reported attack paths were real.
OpenAI has been careful about the attribution. The company said it remains unclear whether every operator involved in the wider activity came from a single organization. However, it attributed a core cluster to people associated with Moonshot AI, the developer of Kimi.
That distinction matters because OpenAI's disclosure does not establish that all 15,000-plus users were connected to Moonshot AI, nor does it say Kimi was trained using the extracted reasoning.
Also Read: OpenAI and Anthropic Under FTC Lens as AI Agent Risks Raise Questions
OpenAI said it responded by banning or restricting accounts involved in the activity and strengthening sign-up, infrastructure and monitoring controls. It also added safeguards around protected reasoning across users, organizations and model families.
The company closed a pathway that could let someone replay another user's encrypted reasoning and recover its contents. OpenAI also said it is working with third-party service providers and sharing information with industry groups and government channels.