OpenAI Says People Linked to China's Moonshot Tried to Copy Its AI's Hidden Reasoning

OpenAI says it disrupted a coordinated campaign that attempted to extract the hidden internal "reasoning" of its models, logging more than 16,000 extraction requests from over 4,000 users on July 24-25 within a broader cluster of more than 15,000 accounts. The company attributes a central cluster of the activity to individuals linked to Moonshot AI, the Chinese startup behind the Kimi chatbot, and says it closed the exploited pathway by July 28.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 6 minutes agoUpdated 6 minutes ago0 views
OpenAI Says People Linked to China's Moonshot Tried to Copy Its AI's Hidden Reasoning

Why It Matters

If successful, reproducing a model's internal reasoning could let adversaries train smaller models to mimic a larger model's capabilities without the original safety controls, accelerating competitive cloning. The attribution to people tied to a company pursuing a large IPO raises commercial and regulatory implications for model security and industry practices.

Key Facts

  • campaign start date: July 1, 2025 (per OpenAI)
  • peak extraction volume: 16,000 extraction requests on July 24-25 from more than 4,000 users
  • cluster size: over 15,000 users involved in the wider cluster
  • disruption date: OpenAI says it fully disrupted the activity by July 28, 2025
  • attribution: OpenAI attributes a core cluster of the activity to individuals associated with Moonshot AI (developer of Kimi)

OpenAI reported it disrupted a coordinated effort that sought to extract the encrypted internal "reasoning" its models generate before producing final answers. According to the company, the campaign began on July 1 and produced a surge of activity on July 24-25, when the service recorded roughly 16,000 extraction requests from more than 4,000 users as part of a broader cluster exceeding 15,000 accounts. OpenAI says it fully blocked the activity by July 28.

The company clarified that attackers did not break encryption keys, access databases, or obtain stored user conversations directly. Instead, operators manipulated model interactions to make the protected, internal scratchpad — the step-by-step reasoning models use internally — reproducible in responses visible to requesters. One described technique involved copying encrypted reasoning from one conversation and prompting a model in another session to decode it.

OpenAI linked a core cluster of the campaign to individuals associated with Moonshot AI, the Chinese startup behind the Kimi chatbot, while noting it was unclear whether all participants were from a single actor. Moonshot had not responded to OpenAI's post; public reporting notes the company is targeting a HKD $3 billion IPO at a reported $50 billion valuation. OpenAI also said it closed the pathway that allowed one user’s encrypted reasoning to be replayed and recovered by another.

OpenAI framed the activity as "adversarial distillation" — the unauthorized use of one model's outputs or reasoning to train or reproduce another model. The company placed the incident in a broader context of similar disputes this year, including OpenAI's earlier extraction concerns, Anthropic's allegations of large-scale fraudulently created accounts, government warnings about foreign distillation campaigns, and academic findings about shared encryption keys that prompted server-side fixes at major providers.

Keep Reading