OpenAI Says People Linked to China's Moonshot Tried to Copy Its AI's Hidden Reasoning

Zusammenfassung:OpenAI says it disrupted a campaign involving 15,000+ users and ties a core cluster to people associated with Moonshot, the startup behind Kimi.

In brief

  • OpenAI says a campaign that began July 1 sent 16,000 extraction requests from more than 4,000 users on July 24-25 alone, within a cluster of over 15,000 users.
  • OpenAI attributes a core cluster of the activity to individuals associated with Moonshot AI, maker of Kimi, and says it is unclear whether all operators came from a single actor.
  • The target was the hidden “reasoning” OpenAI's models generate before answering, which OpenAI says could train another model without the original safeguards.

OpenAI claims to have shut down a coordinated effort to copy the way its AI models think, and it traces a core cluster of that activity to people associated with Moonshot AI, the Chinese startup behind the Kimi chatbot.

The campaign began on July 1, according to OpenAI. On July 24 and 25 alone, it logged 16,000 extraction requests from more than 4,000 users, part of a wider cluster of over 15,000 users. OpenAI says it fully disrupted the activity by July 28.

Myriad: Which company IPOs next? Click to make your prediction.

The target wasn't the answers, but the work behind them.

Modern AI models “reason” before they reply—they work through a problem step by step in an internal scratchpad, then show you a clean result. OpenAI keeps that scratchpad encrypted, and says pulling it out can reveal information the final answer leaves out.

“The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” OpenAI said. “Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.”

One method involved copying encrypted reasoning out of one conversation and asking a model to decode it in another.

OpenAI's post doesn't connect the campaign to K3, but it leaves space for reasonable doubt. “It is unclear whether all operators we observed during the relevant time period originated from a single actor. However, we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi,” OpenAI said.

OpenAI has since closed a pathway that let someone who already had another user's encrypted reasoning replay it to recover its contents.

BitcoinBTC · USD

$84,604+0.24%

24H7D1M1YYTD

Sep 24Sep 26Sep 28Sep 30Oct 1

$85.3k$84.4k$83.5k$82.7k

24h HighHigh$85,183

24h LowLow$83,182

VolVol$1.4B

Market projectionsOdds by Myriad

This weekAbove $84,000Above $84k63% chance

→

Buy Bitcoin with USDT

Powered by Jupiter

$50$100$500

Buy

Price data by CoinGeckoCoinGeckoMore Bitcoin news and projections →

Why would anyone want it? Because distillation—training a new AI on the outputs of a stronger one—leads to better results from smaller models without heavy training.

Done without authorization, OpenAI calls it adversarial distillation: “the systematic and unauthorized use of one model's outputs or reasoning to help train, reproduce, or improve another model.”

This is just one of the many scandals involving AI companies. The most obvious and popular one is the illegal or unauthorized use of copyrighted data to train models. Distillation doesnt go this far. AI outputs are not copyrightable so companies include prohibitions and safeguards in their terms of service to prevent competitors from using those outputs.

A familiar accusation

OpenAI has been here before. In January 2025, it said it was reviewing signs that DeepSeek may have distilled its models, as Washington weighed national security risks.

Anthropic followed in February, accusing Chinese labs of using about 24,000 fraudulent accounts to generate more than 16 million exchanges with Claude. Online critics shot back that Claude itself was trained on the open internet.

By April, the White House was saying foreign entities, primarily in China, were running industrial-scale distillation campaigns. A week later, Elon Musk acknowledged in court that xAI used distillation on OpenAI models to train Grok.

In June, Anthropic took the fight to Congress, asking for penalties for large-scale model extraction.

In August, researchers showed that OpenAI, Anthropic and Google each protected reasoning with a single provider-wide encryption key, and that attackers could coax models into spitting out the hidden thoughts in plain text. All three companies deployed server-side patches after disclosure, though session logs shared earlier remain decodable.

Moonshot hasn't responded to OpenAI's post. Its targeting a $3 billion IPO in Hong Kong at a $50 billion valuation.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Your Email

Get it!

Get it!

Haftungsausschluss

Die Ansichten in diesem Artikel stellen nur die persönlichen Ansichten des Autors dar und stellen keine Anlageberatung der Plattform dar. Diese Plattform übernimmt keine Garantie für die Richtigkeit, Vollständigkeit und Aktualität der Artikelinformationen und haftet auch nicht für Verluste, die durch die Nutzung oder das Vertrauen der Artikelinformationen verursacht werden.
Letzter Artikel

Bitgets Hack in Höhe von 388 Mio. US-Dollar lässt die Verluste im Bereich Krypto-Sicherheit im dritten Quartal auf über 1 Mrd. US-Dollar steigen

Nächste

Evernorth erhält Zustimmung der Aktionäre vor Nasdaq-Debüt mit 473 Mio. XRP im Treasury