
The OpenAI and Moonshot AI logos (illustrative). Image: OpenAI logo via Wikimedia Commons (public domain); Moonshot AI logo via Wikimedia Commons (CNAIPlus, CC0)
OpenAI has accused people linked to Moonshot AI, the Chinese company behind the Kimi chatbot, of trying to copy its models. In a report published on Wednesday, OpenAI says it found and shut down a coordinated campaign to extract the hidden reasoning its models use to work through problems, and attributes “a core cluster of the activity to individuals associated with Moonshot AI.”
What is distillation?
Distillation means training one AI model on the outputs of another, so it picks up the stronger model’s abilities without the same cost. Done without permission, OpenAI calls it adversarial distillation. The target here was what OpenAI calls “protected reasoning”, the model’s internal working that it keeps hidden from users and only shares as a final answer.
OpenAI stresses that nobody broke its encryption, got into a database or reached stored user conversations. Instead, the operators “manipulated model interactions” so the hidden reasoning came back in a form they could see. One trick was to copy encrypted reasoning from one conversation and ask the model, in another conversation, to decrypt it and write it out.
16,000 requests from more than 4,000 users
The activity started on July 1 at a low level. On July 24 and 25 it spiked to 16,000 requests using the same extraction pattern, from more than 4,000 users. OpenAI then traced related activity across a cluster of more than 15,000 users, and says it had fully shut the campaign down by July 28.
OpenAI admits it can’t say whether everyone involved came from a single group, but names Moonshot AI for the core of it. It banned or restricted the accounts, tightened signup controls, closed the route that let someone replay another user’s encrypted reasoning, and added checks to catch streamed output that might expose it. It also worked with third-party services the activity moved through, and shared its findings with other labs through the Frontier Model Forum and with government.
Moonshot AI hasn’t commented on the report. Kimi is one of China’s best-known AI chatbots, and its latest model, Kimi K3, is free to try through NVIDIA’s API.
Not just OpenAI’s problem
OpenAI says the technique “is not a vulnerability unique to OpenAI’s models”. Anthropic said in September that it had found six illicit distillation campaigns by China-based labs since February, as we reported, and this week it warned that a Chinese model anyone can download, Z.ai’s GLM-5.3, can now build working hacks.
OpenAI frames the risk as more than lost business. Reasoning copied this way could train another model “without preserving the safeguards” of the original, and at scale distillation can “accelerate the transfer of advanced capabilities without requiring the same investment in safety,” it says. It expects attempts to get “more sophisticated as frontier models improve”.
Why it matters
It’s a rare case of a US lab publicly naming a Chinese rival over copying. If hidden reasoning can shortcut years of work, protecting it becomes a security problem as much as a business one, which is exactly how OpenAI is now framing it: a risk to safety and national security, not just to its revenue.
Sources: OpenAI: Disrupting a coordinated model-distillation campaign.


