OpenAI says a rival-linked network tried to turn its protected reasoning into raw material for another model. This was not a database breach, but it may be a more consequential kind of raid: industrial-scale extraction conducted through ordinary-looking conversations.
The company’s 30 September disclosure attributes a “core cluster” of the activity to people associated with Moonshot AI, the Chinese developer of Kimi. The allegation is serious, the scale is striking and the public evidence still has limits.
Not a hack — and not harmless scraping
OpenAI says the earliest activity appeared on 1 July. On 24 and 25 July, it observed 16,000 attempted requests using a relevant extraction pattern across more than 4,000 users. Its wider investigation identified related prompt-pattern activity in a cluster of more than 15,000 users, which it says was fully disrupted by 28 July.
Those numbers need disciplined reading. OpenAI’s footnote says the 16,000 requests were attempts, not necessarily successful extractions. It also says it cannot establish that every operator belonged to one actor. Its narrower claim is that individuals associated with Moonshot AI formed a central part of the activity.

That is enough to make the OpenAI–Moonshot AI dispute more than another vague argument about AI model copying. It provides dates, observed patterns and a response timeline. It does not provide account-level evidence or an independent attribution report that outsiders can reproduce.
Encrypted reasoning became the target
The method matters. OpenAI says operators copied encrypted reasoning from one conversation, then asked a model in another conversation to decrypt and transcribe the hidden reasoning. They did not break encryption, enter a database or gain direct access to stored user chats. Instead, they allegedly manipulated model interactions to make protected reasoning visible.
Independent researchers had already exposed the broader weakness. In Stealing Reasoning Traces from Proprietary LLM APIs, eight researchers described encrypted reasoning blocks that could be replayed across sessions, users and models within a provider’s ecosystem. Their tests covered Anthropic, OpenAI and Google.
The team says it decoded 315,320 reasoning blocks gathered from public repositories, recovering 367 pieces of personally identifiable information and 182 credentials. Those figures come from the separate research dataset, not from the alleged Moonshot campaign. They demonstrate the attack class, not Moonshot’s responsibility.

That distinction is crucial. A reproducible vulnerability can support OpenAI’s explanation of the mechanism without independently proving who ran a particular campaign.
Distillation has a permission problem
Model distillation is not automatically misconduct. Developers routinely use a stronger model’s outputs to train or improve a smaller one when the provider permits it. The controversy begins when output harvesting is concealed, coordinated and designed to defeat safeguards or contractual restrictions.
OpenAI’s warning is that extracted reasoning could transfer advanced capabilities without transferring the safety work wrapped around the original system. As models move deeper into cyber security, biology and autonomous tool use, copying capability without copying controls is not merely an intellectual-property quarrel.
Yet frontier laboratories have an obvious interest in defining the boundary broadly. A company that trained on enormous quantities of internet material now argues that systematic use of its own outputs is beyond the line. That does not invalidate its case, but it makes transparent evidence and consistent rules essential.
The accusation still needs daylight
BankInfoSecurity reported that Moonshot had previously faced similar accusations from Anthropic. As of 1 October, no public response from Moonshot to this specific OpenAI disclosure was located in Bullish Times’ checks. Silence is not an admission.
OpenAI says it banned or restricted fraudulent accounts, tightened sign-up and infrastructure controls, expanded network monitoring and closed the replay pathway. It also added checks intended to hold streamed output that might expose reasoning, and shared findings through the Frontier Model Forum and government channels.
Those are sensible defences, but they leave the market judging the prosecutor’s evidence from the prosecutor’s summary. A stronger disclosure would separate confirmed successful extraction from attempted requests, explain the attribution standard and publish technical indicators that peers can validate without exposing active defences.
The next AI moat is enforcement
The Kimi controversy reveals an awkward truth about frontier AI. If a model’s most valuable behaviour can be queried, replayed and reconstructed at scale, capability is not protected simply because its weights are closed.
The next phase will be less about a single clever filter and more about identity, rate patterns, cross-account coordination, cryptographic binding and consistent controls across first-party and cloud-hosted deployments. OpenAI itself says partner systems and tool-output attacks still need stronger protection.
Moonshot deserves a chance to answer a carefully bounded allegation. OpenAI, having named a rival, should eventually show enough evidence for the industry to distinguish attribution from competitive rhetoric. Until then, the 15,000-user cluster is both a warning and a claim under examination.
The AI race is no longer just about who can build the smartest model; it is about who can stop that model becoming somebody else’s training set.










