Skip to content
nanoai

OpenAI links Moonshot AI to a bid to extract its hidden reasoning

Users sent 16,000 requests in two days trying to get OpenAI’s own models to decode their encrypted chain of thought. The encryption held. The loophole was the model.

By The Nano AI Staff3 min read

AI companies news graphic showing OpenAI linking Moonshot AI to an alleged attempt to extract hidden reasoning from AI models, with digital brain visualizations, cybersecurity monitoring screens, and model extraction warning indicators.
Image: AI Generated

Key takeaways

  • OpenAI tied a core cluster of a July campaign to extract its hidden reasoning to Moonshot AI.
  • Operators asked one conversation’s model to decrypt reasoning copied from another.
  • OpenAI gave no technical evidence for the attribution; Moonshot has not publicly responded.

OpenAI said on Wednesday, September 30, that it had broken up a coordinated campaign to pull hidden reasoning out of its models, and it pinned “a core cluster of the activity” on individuals associated with Moonshot AI, the Chinese company behind the Kimi chatbot. The activity began at low volume on July 1, spiked on July 24 and 25 with 16,000 requests from more than 4,000 users, and was fully disrupted by July 28, after OpenAI had traced related patterns across more than 15,000 users.

Moonshot has not answered publicly. CyberScoop said it had asked the company for comment.

The encryption held. The model did the decoding.

Reasoning models work through a problem before they answer, and OpenAI keeps that working hidden. It calls protected reasoning “the model’s internal record for working through a task”, and says extracting it “can reveal information withheld from the final answer and help others reproduce the model’s capabilities”. That is why it is worth so much to a rival. It is the closest thing to watching the model think.

The method was simple. The operators copied encrypted reasoning from one conversation and asked a model in another conversation to decrypt and transcribe it. “The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” OpenAI says.

Here is the detail most coverage glides past. The cipher was fine. The weakness was that a system able to read the protected text would read it back when asked. OpenAI says it has closed a pathway that let someone who already held another user’s encrypted reasoning replay it and recover its contents, added checks that hold back streamed output that might expose reasoning, and strengthened its sign-up controls.

Why the Moonshot name now

The disclosure lands in a crowded file. In early September the NSA, CISA and FBI issued a joint advisory naming six China-based AI companies. It said Moonshot AI “has conducted a widespread distillation campaign against U.S. frontier AI companies since at least mid-2025”. Distillation means training a cheaper model on a stronger model’s outputs. The advisory said the sector had turned to it “likely with the knowledge of the Chinese government”, and suggested that providers could answer suspected distillers with “downgraded” models.

Anthropic made its own case earlier. Its report on distillation attacks, first published in February and updated on September 9, says Moonshot ran over 3.4 million exchanges with Claude and, in a later phase, attempted “to extract and reconstruct Claude’s reasoning traces”. In July, Moonshot denied that its Kimi K3 model was built through distillation, Tom’s Hardware reports.

OpenAI is careful to separate the practice from the principle. “Our concern is about violation of our terms of service, not open models or legitimate distillation,” Caroline Zier, who leads strategic national security policy initiatives at OpenAI, told Bloomberg, according to The Next Web.

What the post does not prove

Read the wording closely. OpenAI attributes a “core cluster” to “individuals associated with” Moonshot, and it says it is unclear whether all the operators it saw came from a single actor. CyberScoop notes that the post offers no technical evidence for the attribution. That is common in company threat reports, but it means outsiders cannot test the claim.

Then there is the gap in time. The campaign was shut down on July 28. The public account came two months later, after Washington had already named Moonshot. OpenAI says it shared information with other labs through the Frontier Model Forum in the meantime.

Who gains and who loses

US labs gain a public argument for tighter controls on reasoning features and on sign-ups, and the federal advisory has already suggested answering suspected copiers with downgraded models. Ordinary developers may feel that as extra friction. For Chinese labs, each named case makes it harder to sell into markets that now treat distillation as a security issue rather than a terms-of-service dispute.

What to watch: whether Moonshot responds on the record, whether OpenAI or the US agencies publish indicators that others can check, and whether other providers report the same decryption trick against their own reasoning features.

  • OpenAI
  • Moonshot AI
  • Distillation
  • AI security
  • China

Sources

  1. Disrupting a coordinated model distillation campaign — OpenAI, Sep 30, 2026
  2. OpenAI reveals ‘novel’ encryption bypass used in distillation attack — CyberScoop, Sep 30, 2026
  3. China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — NSA, CISA and FBI (Joint Cybersecurity Advisory), Sep 8, 2026
  4. Detecting and preventing distillation attacks — Anthropic, Feb 23, 2026
  5. OpenAI says actors linked to China-based Moonshot AI spearheaded a campaign to extract its models’ hidden reasoning — logged 16,000 extraction requests across 4,000 accounts before cutoff — Tom's Hardware, Oct 1, 2026
  6. OpenAI says Moonshot-linked users tried to extract its AI reasoning — The Next Web, Sep 30, 2026

Follow The Nano AI: Instagram · X · LinkedIn · YouTube

Was this article helpful?

Comments

No comments yet. Start the conversation.

Be respectful. Comments are moderated.

Related stories

The AI briefing, without the noise.

The stories that matter in AI, sourced and explained. Free, and you can unsubscribe at any time.