OpenAI has pointed fingers at individuals connected to Chinese artificial intelligence firm Moonshot AI, alleging they attempted to extract protected reasoning data from its models. The purported operation kicked off on July 1, 2026, targeting OpenAI’s online systems to aid in model distillation. According to OpenAI, the actors manipulated how they interacted with the models rather than breaching databases or gaining unauthorized access to saved chat histories.
Activity spiked on July 24 and July 25, during which OpenAI logged 16,000 extraction-style requests originating from more than 4,000 users. Subsequent probes revealed comparable prompting behavior spanning over 15,000 users prior to OpenAI halting the campaign on July 28. The firm tied a primary cluster of these accounts to people linked with Moonshot AI, the creators of Kimi.
OpenAI characterized the maneuver as adversarial distillation, pointing to efforts to pull out reasoning steps that are typically kept out of final outputs. One method involved copying encrypted reasoning from an initial chat session and prompting a separate interaction to decrypt it. OpenAI clarified that the operators never bypassed encryption nor compromised archived user chats.
Additionally, the company emphasized that these numbers reflect attempted extractions instead of verified successful data hauls. OpenAI has not revealed the volume of protected reasoning the operators managed to secure during the push.
The most significant unresolved question is whether Kimi AI actually utilized the purported ChatGPT reasoning for training purposes. OpenAI’s statement stops short of proving this link, leaving the accusation regarding Kimi’s training unverified. Furthermore, the organization did not attribute every single account within the broader 15,000-user network directly to Moonshot AI.
In response, OpenAI stated it placed restrictions on accounts, upgraded registration barriers, and tightened surveillance across associated networks. The enterprise also shut down a vector that allowed encrypted reasoning to be replayed and introduced new output checks designed to block the exposure of protected reasoning.
“Adversarial distillation poses safety and national security risks,” OpenAI stated, cautioning that pilfered reasoning could facilitate the replication of sophisticated capabilities. The firm noted that such tactics risk transferring capabilities without requiring a matching investment in safety protections.
These claims intensify existing scrutiny surrounding Moonshot AI and the practice of AI model distillation. In a separate development, Anthropic has accused Moonshot alongside other Chinese AI creators of large-scale distillation targeting Claude models. While this background adds context, it does not independently verify whether Kimi was trained on OpenAI’s extracted reasoning.
At present, the available evidence points to an alleged OpenAI model distillation campaign tied to individuals associated with Moonshot. However, it does not confirm that ChatGPT reasoning was used to train Kimi, nor does it establish that Moonshot controlled every account involved.
Also Read: China Probes DeepSeek, Moonshot AI Over Claude Data Routing Claims




