OpenAI states it shut down a coordinated operation designed to replicate how its artificial intelligence models think. The company traces a primary cluster of this activity to individuals linked with Moonshot AI. Moonshot AI is the Chinese startup that created the Kimi chatbot.
The campaign launched on July 1. OpenAI recorded 16,000 extraction requests from more than 4,000 users on July 24 and July 25 alone. This surge formed part of a broader cluster involving over 15,000 users. OpenAI successfully disrupted the entire activity by July 28.
OpenAI explains how the extraction occurred
Modern artificial intelligence models reason before they answer. They process problems step by step on an internal scratchpad before providing a clean output. OpenAI encrypts this scratchpad. Extracting it can expose details that the final response omits.
Operators did not break encryption, breach a database, or gain direct access to stored user conversations. Instead, operators manipulated model interactions so protected reasoning appeared in forms visible to the requester at scale. This maneuver violated platform terms of service.
One technique required copying encrypted reasoning from one conversation and instructing a model to decode it in another. OpenAI notes its post does not directly link the campaign to the K3 model. However, the company states a core cluster of the activity ties back to people associated with Moonshot AI.

Unauthorized distillation drives the technique
OpenAI closed a vulnerability that permitted users with another person's encrypted reasoning to replay it and recover the contents. Distillation involves training a new artificial intelligence on the outputs of a stronger one. This process yields better performance from smaller models without requiring heavy training.
OpenAI terms unauthorized distillation adversarial distillation. The company defines this as the systematic and unauthorized use of outputs or reasoning from one model to train, reproduce, or improve another model. AI outputs lack copyright protection. Companies rely on terms of service and safeguards to stop competitors from utilizing those outputs.
OpenAI previously stated in January 2025 that it reviewed signs indicating DeepSeek may have distilled its models as Washington evaluated national security risks. Anthropic accused Chinese labs in February of utilizing roughly 24,000 fraudulent accounts to generate over 16 million exchanges with Claude. The White House stated in April that foreign entities, primarily in China, operated industrial scale distillation campaigns. Elon Musk admitted in court a week later that xAI used distillation on OpenAI models to train Grok.
Read nextOpenAI and Synopsys Partner to Build AI Chip Design ModelIndustry pressure mounts against extraction
Anthropic urged Congress in June to establish penalties for large scale model extraction. Researchers demonstrated in August that OpenAI, Anthropic, and Google each secured reasoning using a single provider wide encryption key. Attackers could coax models into exposing hidden thoughts in plain text. All three corporations deployed server side patches after disclosure, although previously shared session logs remain decodable.
Moonshot has not responded to the public claims made by OpenAI. The startup currently targets a $3 billion initial public offering in Hong Kong at a $50 billion valuation.



