Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else
OpenAI says it disrupted a July distillation campaign tied to Moonshot AI that copied protected model reasoning.
OpenAI said it disrupted an adversarial distillation campaign through most of July 2026 that it links to China's Moonshot AI, maker of Kimi. Operators did not break encryption or access stored chats; they sent bulk queries to reproduce protected reasoning, including 16,000 patterned requests from over 4,000 users on July 24-25 and related activity across more than 15,000 users. OpenAI banned accounts, closed a replay path for encrypted reasoning, and shared findings through the Frontier Model Forum. US officials and Anthropic have separately accused Moonshot of distilling American models, including claims about Kimi K3 and Anthropic's Fable.
- Campaign ran July 1-28; OpenAI says it fully disrupted it.
- July 24-25 spikes: 16,000 extraction requests from over 4,000 users.
- Core cluster attributed to Moonshot AI; not every operator confirmed.
- No encryption break or database access; scaled terms-of-service abuse.
- OpenAI warns extracted reasoning could train models without original safeguards.
Full article564 words · extracted from theregister.com · click to collapse
REG AD
security
US model makers can train on web data - but distilling theirs is a 'national security risk'
OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China’s Moonshot AI of being involved in a "distillation attack" that began July 1. The house of Altman warns that extracting its models’ reasoning at scale could help rivals train capable models without preserving the same guardrails.
Model distillation is a machine learning technique that can involve using one model’s outputs to train another – in adversarial cases, by sending bulk queries designed to reproduce the larger model’s reasoning and capabilities.
Both the feds and major US AI companies, including Google and Anthropic, have accused Chinese rivals - and specifically Moonshot AI - of using distillation to reproduce capabilities from American models. In a Wednesday blog, OpenAI chimed in, saying it spotted and ultimately disrupted an adversarial distillation campaign that ran nearly all of July.
REG AD
“The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” according to the blog. “Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.”
REG AD
The queries began on July 1, and while they started slowly, “we observed high-volume spikes on July 24 and 25 consisting of 16,000 requests using a relevant extraction pattern from over 4,000 users,” OpenAI said.
Upon investigating the incident, the AI giant identified related “prompt-pattern activity” across more than 15,000 users. OpenAI fully disrupted the campaign on July 28, we’re told.
While OpenAI said that it's unclear whether all of the operators during the July time period were linked to just one rival AI company, the “core cluster” of the theft came from Moonshot AI, which developed Kimi.
The Register reached out to Moonshot AI for comment and did not receive an immediate response. We also asked OpenAI which of its models were targeted during the July campaign, but did not hear back.
It’s worth noting that, in late July, US President Donald Trump’s Assistant for Science and Technology Michael Kratsios also accused Moonshot AI of creating its Kimi K3 model by distilling Anthropic’s Fable.
Anthropic’s Claude Opus 5.5 model, released a week ago, comes with a defense against distillation called "preserved thinking" that it introduced with Fable 5.1.
“Adversarial distillation poses safety and national security risks,” OpenAI said on Wednesday, echoing earlier gripes from American companies and government officials.
“Extracted reasoning could be used to train another model without preserving the safeguards applied to the original model’s user-facing outputs,” OpenAI added. “At scale, distillation can also accelerate the transfer of advanced capabilities without requiring the same investment in safety. These concerns become heightened as models gain capabilities in dual use domains.”
REG AD
In response, OpenAI said it banned the model-copying accounts tightened signup and infrastructure controls and expanded monitoring efforts.
It also “closed a pathway that allowed someone who already possessed another user's encrypted reasoning to replay it and recover its contents,” and worked with service providers to ensure that this type of distillation activity didn’t just move to third-party services.
Additionally, OpenAI shared the details of its investigation with other AI firms, through the Frontier Model Forum, and government information-sharing programs.®