
OpenAI accuses Chinese developer Moonshot of harvesting AI reasoning data
OpenAI disrupted an adversarial distillation campaign in July 2026 that generated 16,000 requests from thousands of accounts linked to Chinese AI lab Moonshot.
Coordinated distillation campaign
OpenAI published a blog post on Wednesday disclosing that it disrupted a coordinated campaign designed to extract protected reasoning from its artificial intelligence models. The company traced a core cluster of the extraction effort to individuals associated with Moonshot AI, the Chinese developer behind the Kimi model. The unauthorized activity initially began on 1 July 2026 at low volume before increasing substantially toward the end of the month.
The distillation operation reached its peak on 24 and 25 July 2026, when operators generated 16,000 requests from more than 4,000 separate user accounts within two days. OpenAI later detected related extraction activity spanning more than 15,000 accounts across its platform. The company confirmed that it fully shut down the campaign on 28 July 2026. Although OpenAI did not tie every individual participant to a single entity, it attributed the primary cluster of accounts to people linked with Moonshot.
OpenAI described the technical nature of the activity in its official statement.
This activity is consistent with adversarial distillation: the systematic and unauthorized use of one model's outputs or reasoning to help train, reproduce, or improve another model,
- Model reasoning extraction begins at low volume
- Queries peak at 16,000 over two days across more than 4,000 users
- OpenAI shuts down the campaign and terminates associated accounts
- OpenAI publicly attributes a core cluster of the campaign to Moonshot
Extraction method and technical defenses
The extraction campaign focused on accessing the internal reasoning steps that OpenAI systems generate before delivering a final response to user prompts. Because OpenAI hides this reasoning process from standard outputs, operators copied the encrypted reasoning text from one conversation session. The users then submitted that encrypted material into a different conversation, prompting the model to decrypt and transcribe the underlying reasoning.
OpenAI reported that the operators did not breach underlying encryption, compromise internal databases, or gain access to stored user conversations. Following the discovery, the developer banned the identified accounts, introduced stricter sign-up checks for new users, and deployed additional technical safeguards to protect model reasoning. OpenAI also shared its technical findings with rival artificial intelligence laboratories through the Frontier Model Forum and provided details directly through United States government channels.
Caroline Zier, who leads strategic national security policy initiatives at OpenAI, clarified the company's position on the enforcement actions.
Our concern is about violation of our terms of service, not open models or legitimate distillation,
Industry disputes and regulatory scrutiny
The blog post marks the first time OpenAI has publicly accused Moonshot of unauthorized model extraction. The accusation follows a similar finding published last month by Anthropic, which also accused Moonshot of attempting to extract proprietary model capabilities. These claims match findings from United States government agencies, which issued an advisory earlier this month identifying six Chinese companies alongside the specific American AI models each firm allegedly targeted. The Chinese government rejected the advisory, characterizing the findings as unfounded accusations.
The claims have generated debate among policy figures regarding international competition in artificial intelligence. David Sacks, the former AI czar under Donald Trump, described such corporate reports as an effort to encourage United States authorities to ban rival open models. Meanwhile, Moonshot is contending with regulatory scrutiny domestically in China, where government regulators opened investigations into both Moonshot and peer developer DeepSeek earlier this month.

