

OpenAI has accused individuals linked to Chinese AI company Moonshot AI of extracting protected reasoning from its models. The campaign allegedly began on July 1, 2026, and targeted OpenAI systems online to support model distillation efforts. OpenAI says operators manipulated model interactions instead of hacking databases or accessing stored conversations.
The activity surged on July 24 and 25, when OpenAI recorded 16,000 extraction-pattern requests from over 4,000 users. Further investigation found similar prompt activity across more than 15,000 users before OpenAI disrupted the campaign by July 28. The company linked a core cluster to individuals associated with Moonshot AI, which develops Kimi.
OpenAI described the operation as adversarial distillation, involving attempts to expose reasoning normally hidden from final answers. One reported method copied encrypted reasoning from one conversation before another interaction requested its decryption. OpenAI said the operators did not break encryption or compromise stored user conversations.
The company also stressed that the reported figures represent attempted extractions, rather than confirmed successful retrievals. OpenAI has not disclosed how much protected reasoning operators obtained during the campaign.
The biggest question concerns whether Kimi AI actually used the allegedly extracted ChatGPT reasoning for training. OpenAI’s disclosure does not establish that connection, leaving the claim about Kimi training unproven. The company also did not attribute every account within the wider 15,000-user cluster to Moonshot AI.
OpenAI said it responded by restricting accounts, improving signup controls and strengthening monitoring across related networks. The company also closed a pathway that could replay encrypted reasoning and added checks for outputs that might expose protected reasoning.
“Adversarial distillation poses safety and national security risks,” OpenAI said, warning that extracted reasoning could help reproduce advanced capabilities. The company added that such activity could transfer capabilities without matching investment in safety safeguards.
The allegations add to wider scrutiny around Moonshot AI and AI model distillation. Anthropic has separately accused Moonshot and other Chinese AI developers of large-scale distillation involving Claude models. Those allegations provide context but do not independently prove that Kimi used OpenAI’s extracted reasoning.
For now, the evidence supports an alleged OpenAI model distillation campaign linked to Moonshot-associated individuals. It does not establish that ChatGPT reasoning trained Kimi or that Moonshot operated every account involved.
Also Read: China Probes DeepSeek, Moonshot AI Over Claude Data Routing Claims