OpenAI says it shut down a coordinated effort to extract the hidden reasoning inside its models, and has linked the core of that activity to people associated with Moonshot AI, the Chinese company behind the Kimi chatbot. The campaign started on 1 July at low volume and peaked on 24 and 25 July with 16,000 prompts from more than 4,000 users, OpenAI said in a disclosure on 30 September, with related activity eventually spanning more than 15,000 accounts before the company cut it off on 28 July.
The method was unusual. OpenAI's reasoning models work through a problem in steps that users never see, and those steps are encrypted. Rather than attack the encryption, the operators copied the encrypted reasoning out of one conversation and then asked the model, in a separate conversation, to decrypt and write it out in plain text. "The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations," OpenAI said.
The company banned the accounts, tightened sign-up controls, widened its network monitoring, fixed the flaw that allowed data to move between conversations and shared what it found with the Frontier Model Forum, an industry body. It framed the issue narrowly: "Our concern is about violation of our terms of service, not open models or legitimate distillation." Moonshot has not responded publicly to the specific claims, and has said its results come from its own work rather than copying American models.
What Distillation Means Here
Distillation is a standard technique in machine learning: a smaller model is trained on the outputs of a larger one, learning to imitate its behaviour at lower cost. Done with permission, or on openly licensed models, it is ordinary engineering and widely used.
What the frontier labs object to is distillation done against their paid APIs in breach of the terms customers agree to, and in particular attempts to capture reasoning traces. Those step-by-step chains are the part of a reasoning model that is hardest and most expensive to produce, since they come from extensive reinforcement learning, and a rival that collects enough of them can train a model to reason in a similar way without repeating that work.
Why The Labs Hide Their Reasoning
That is also why the reasoning is hidden in the first place. Frontier developers show users a summary of a model's thinking rather than the raw chain, partly for safety monitoring and partly to protect what they consider their most valuable output.
OpenAI's account suggests the protection held technically, in that the encryption was never broken, while the model itself became the weak point when asked to transcribe material it should not have surfaced. It is a reminder that in AI systems the model's willingness to follow instructions can undo controls built around it.
A Month Of Accusations
The OpenAI disclosure is the third major claim of its kind in three weeks. On 9 September, the NSA, FBI and CISA published an advisory naming six Chinese AI companies they said had extracted capabilities from US models: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The agencies said distillation formed the core of these companies' model development rather than a supplement to it, and described the use of fraudulent accounts, cloud routing and proxy services to avoid detection.
A day later, Anthropic published a threat report detailing campaigns it attributed to Alibaba, Moonshot and DeepSeek, counting nearly 200 million exchanges across five operations. It said the largest involved 151 million exchanges through 3,500 accounts between May and July, and that a separate effort ran about 300,000 requests over ten days through thousands of proxy accounts registered in Singapore and Japan, aimed at its Claude Opus model. Anthropic also alleged that Moonshot had at times routed requests from its own Kimi users to Claude and presented the answers as Kimi's.
China's foreign ministry rejected the US advisory the day after it appeared, with spokesperson Mao Ning calling the claims "unfounded accusations and smears" and describing the country's AI progress as the result of technological self-reliance.
The Evidence Is The Labs' Own
A caution runs through all of this. The attribution rests on telemetry held by the companies making the accusations, and none of it has been independently audited in public. OpenAI did not publish the technical reasoning behind its link to Moonshot, and Anthropic's figures come from its own systems.
The accused companies are also commercial rivals whose models compete directly with those of the accusers, often at far lower prices, which gives readers reason to weigh the claims carefully even where the underlying activity looks well documented.
Why Businesses Should Pay Attention
The dispute has practical consequences for companies choosing AI models. Chinese open-weight models have become genuinely competitive, and Moonshot's Kimi K3, released in July with 2.8 trillion parameters, can be downloaded and run on a company's own hardware, which appeals to firms that want to keep data in house or avoid per-token API costs.
If US scrutiny hardens into sanctions or procurement restrictions, companies that have built products on those models could face sudden questions about support, licensing and legal exposure. Treasury officials have already raised the possibility of sanctions against Moonshot, so businesses weighing an open-weight Chinese model for a product roadmap should consider that risk alongside price and performance.
Tighter API Controls Are Coming
The other consequence lands on everyone who uses frontier APIs. The labs are responding with stricter sign-up checks, more network monitoring and faster bans, and the US advisory went further, recommending that providers quietly alter outputs sent to suspected distillers without telling them.
Legitimate customers running high volumes of queries, especially automated agents that generate large numbers of similar requests, may find themselves flagged by systems designed to catch distillation. Companies building on these APIs should expect more identity verification and should keep their usage patterns explainable, a discipline that matters anyway once AI agents run devices and systems on a company's behalf.
The Fight Is Over What Models Learn From Each Other
Three accusations in three weeks, from two US labs and three federal agencies, show that the competition between American and Chinese AI developers has moved from benchmarks to questions of how each side's models were trained. The technical detail in OpenAI's account, a model persuaded to transcribe its own protected reasoning, shows how difficult that is to police, since the material the labs want to protect is the very thing their products produce on request.
For businesses, the useful question is not who copied whom but what it changes in their own plans. Expect tighter controls and more identity checks on frontier APIs, more political risk attached to Chinese open-weight models, and a widening gap between the two ecosystems that will make switching between them harder than a price comparison suggests.