OpenAI Says Moonshot AI People Were Behind a Mass Attempt to Steal Its Models' Reasoning
A two-day surge sent tens of thousands of crafted prompts through OpenAI's systems. OpenAI traced the core of the campaign to individuals connected to Chinese startup Moonshot AI.

Key points
- OpenAI linked the core of a coordinated extraction campaign to individuals associated with Moonshot AI, the Chinese startup behind the Kimi chatbot, in July 2026.
- The campaign peaked at 16,000 requests from over 4,000 users across two days, with related activity spanning more than 15,000 accounts in total.
- OpenAI says it fully disrupted the operation by 28 July 2026 and shared findings with other AI developers and government channels.
- No databases, stored conversations or user accounts were breached; attackers manipulated conversations to surface hidden reasoning.
- Anthropic separately accused Moonshot AI and Alibaba of using its Claude model to train competing systems, first reported by CNBC Tech.
Here is the blunt version: someone tried to trick OpenAI's models into showing their work, copy that work down, and use it to build a cheaper rival. OpenAI says the people behind the bulk of it are connected to Moonshot AI, the Chinese company whose Kimi chatbot has been one of the faster-growing AI products outside the United States.
The technique has a name inside the industry: adversarial distillation. Think of it like this. A top chef keeps a recipe secret, but if you order enough dishes and watch closely, you can reverse-engineer the method. Here, operators sent thousands of carefully crafted prompts designed to make the model expose its hidden step-by-step reasoning, the internal logic it normally keeps private. Get enough of those traces and you can train your own model to reason the same way, without spending the billions OpenAI spent developing it.
What actually happened?
OpenAI shut it down by 28 July.
The operators never got inside OpenAI's systems in the traditional sense. Passwords were not the target, and no encryption was broken. They worked the conversation layer, the normal back-and-forth of a chatbot session, manipulating it until hidden reasoning appeared in responses. OpenAI says it is unclear whether a single actor ran everything, but attributed the core cluster to people with ties to Moonshot AI. Moonshot did not respond to requests for comment.
| Timeline | Detail |
|---|---|
| Early July 2026 | Campaign begins |
| Peak (two-day surge) | ~16,000 requests, 4,000+ users |
| Total linked accounts | 15,000+ |
| 28 July 2026 | OpenAI declares full disruption |
| Findings shared | Frontier Model Forum and government channels |
Should you be worried about your own data?
For ordinary ChatGPT users, the short answer is no. OpenAI was clear that no user conversations or stored data were exposed. The attack targeted the model's reasoning process, not your account.
The bigger picture is strategic. If adversarial distillation works at scale, a well-funded team can inherit years of safety research without doing the underlying work. OpenAI argues that creates national security risks, not just a commercial disadvantage.
This is not the first time Moonshot AI has appeared in these pages recently. Our 17 September story, "Moonshot AI wants $2 billion in revenue by year-end, even as it faces theft allegations", found the lab chasing a revenue target double its August run rate while Anthropic accusations were already circling. The pattern around Moonshot is piling up fast, and the company has not answered any of it publicly.



