h.sHamid Samir
All stories

OpenAI says a network linked to Moonshot AI targeted protected model reasoning

OpenAI says a coordinated adversarial-distillation campaign used thousands of accounts to try to extract protected reasoning, attributing a core cluster to people associated with Moonshot AI.

OpenAI says it identified and disrupted a coordinated campaign intended to extract protected reasoning from its models. The company describes the activity as adversarial distillation: the unauthorized use of a model’s outputs or reasoning to train, reproduce, or improve another model.

According to OpenAI, the operators did not break its encryption, compromise a database, or gain direct access to stored user conversations. One technique involved copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe it.

OpenAI says the activity began on July 1 and spiked on July 24 and 25, when it recorded about 16,000 requests using a relevant extraction pattern from more than 4,000 users. A broader investigation found related prompt-pattern activity across a cluster of more than 15,000 users, which the company says it had fully disrupted by July 28. OpenAI notes that these figures describe attempted, not necessarily successful, extractions.

The company says it is unclear whether every operator belonged to one actor, but attributes a core cluster to individuals associated with Moonshot AI, the developer of Kimi. That attribution is OpenAI’s assessment, and the initial report includes no response from Moonshot.

لوگوی Moonshot AI با نشان دایره‌ای مشکی در کنار نام شرکت
لوگوی Moonshot AI با نشان دایره‌ای مشکی در کنار نام شرکت