OpenAI has verified that it successfully dismantled a synchronized effort designed to siphon proprietary reasoning capabilities from its artificial intelligence models. A central group involved in these operations has been traced back to individuals linked with Moonshot AI, the Chinese enterprise responsible for developing Kimi AI models.
The campaign kicked off on July 1, 2026, and picked up significant momentum as the month went on, peaking with 16,000 queries distributed among upwards of 4,000 accounts on July 24 and 25, according to OpenAI. The organization noted that it tracked related behavior spanning more than 15,000 users and completely neutralized the threat by July 28.
How the Reasoning Extraction Campaign Worked
OpenAI characterized the operations as adversarial distillation—a method where the outputs or internal reasoning steps of a leading AI are methodically gathered to train, replicate, or enhance a competing system. The organization emphasized that these metrics represent attempted extractions and do not confirm the actual volume of confidential reasoning data successfully acquired.
OpenAI clarified that the perpetrators bypassed no encryption, breached no databases, and failed to gain direct access to stored user chats. Rather, they manipulated dialogues between models to expose protected reasoning logic to the end user.
One approach utilized involved taking encrypted reasoning segments from a specific dialogue and instructing a model in a separate chat to decode and write out the concealed text. Independent security analysts also flagged similar vulnerabilities tied to cross-model communications and conversation compaction, OpenAI stated. Following an investigation, the company verified that these reported attack vectors were genuine.
Openai Links A Core Cluster to Moonshot Ai
OpenAI exercised caution regarding attribution, pointing out that it is still undetermined whether every participant in the broader campaign belonged to a single entity. Nevertheless, a primary cluster of activity was tied directly to personnel connected to Moonshot AI, the creators of the Kimi platform.
This differentiation is crucial, as OpenAI’s report does not confirm that the entire pool of over 15,000 users had ties to Moonshot AI, nor does it assert that Kimi models were ultimately trained using the harvested reasoning material.
Also Read: OpenAI and Anthropic Under FTC Lens as AI Agent Risks Raise Questions
OpenAI Strengthens Protections After the Incident
In response, OpenAI reported that it banned or restricted accounts tied to the operation while upgrading its registration, infrastructure, and surveillance measures. Additional guardrails were also deployed regarding protected reasoning mechanisms across various users, corporate accounts, and model lineages.
The company patched a vulnerability that previously allowed individuals to replay another user’s encrypted reasoning data to retrieve its underlying information. Furthermore, OpenAI is collaborating with external service providers while distributing threat intelligence to industry associations and government entities.




