OpenAI links Moonshot AI to a bid to extract its hidden reasoning
Users sent 16,000 requests in two days trying to get OpenAI’s own models to decode their encrypted chain of thought. The encryption held. The loophole was the model.

Key takeaways
- OpenAI tied a core cluster of a July campaign to extract its hidden reasoning to Moonshot AI.
- Operators asked one conversation’s model to decrypt reasoning copied from another.
- OpenAI gave no technical evidence for the attribution; Moonshot has not publicly responded.
OpenAI said on Wednesday, September 30, that it had broken up a coordinated campaign to pull hidden reasoning out of its models, and it pinned “a core cluster of the activity” on individuals associated with Moonshot AI, the Chinese company behind the Kimi chatbot. The activity began at low volume on July 1, spiked on July 24 and 25 with 16,000 requests from more than 4,000 users, and was fully disrupted by July 28, after OpenAI had traced related patterns across more than 15,000 users.
Moonshot has not answered publicly. CyberScoop said it had asked the company for comment.
The encryption held. The model did the decoding.
Reasoning models work through a problem before they answer, and OpenAI keeps that working hidden. It calls protected reasoning “the model’s internal record for working through a task”, and says extracting it “can reveal information withheld from the final answer and help others reproduce the model’s capabilities”. That is why it is worth so much to a rival. It is the closest thing to watching the model think.
The method was simple. The operators copied encrypted reasoning from one conversation and asked a model in another conversation to decrypt and transcribe it. “The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” OpenAI says.
Here is the detail most coverage glides past. The cipher was fine. The weakness was that a system able to read the protected text would read it back when asked. OpenAI says it has closed a pathway that let someone who already held another user’s encrypted reasoning replay it and recover its contents, added checks that hold back streamed output that might expose reasoning, and strengthened its sign-up controls.
Why the Moonshot name now
The disclosure lands in a crowded file. In early September the NSA, CISA and FBI issued a joint advisory naming six China-based AI companies. It said Moonshot AI “has conducted a widespread distillation campaign against U.S. frontier AI companies since at least mid-2025”. Distillation means training a cheaper model on a stronger model’s outputs. The advisory said the sector had turned to it “likely with the knowledge of the Chinese government”, and suggested that providers could answer suspected distillers with “downgraded” models.
Anthropic made its own case earlier. Its report on distillation attacks, first published in February and updated on September 9, says Moonshot ran over 3.4 million exchanges with Claude and, in a later phase, attempted “to extract and reconstruct Claude’s reasoning traces”. In July, Moonshot denied that its Kimi K3 model was built through distillation, Tom’s Hardware reports.
OpenAI is careful to separate the practice from the principle. “Our concern is about violation of our terms of service, not open models or legitimate distillation,” Caroline Zier, who leads strategic national security policy initiatives at OpenAI, told Bloomberg, according to The Next Web.
What the post does not prove
Read the wording closely. OpenAI attributes a “core cluster” to “individuals associated with” Moonshot, and it says it is unclear whether all the operators it saw came from a single actor. CyberScoop notes that the post offers no technical evidence for the attribution. That is common in company threat reports, but it means outsiders cannot test the claim.
Then there is the gap in time. The campaign was shut down on July 28. The public account came two months later, after Washington had already named Moonshot. OpenAI says it shared information with other labs through the Frontier Model Forum in the meantime.
Who gains and who loses
US labs gain a public argument for tighter controls on reasoning features and on sign-ups, and the federal advisory has already suggested answering suspected copiers with downgraded models. Ordinary developers may feel that as extra friction. For Chinese labs, each named case makes it harder to sell into markets that now treat distillation as a security issue rather than a terms-of-service dispute.
What to watch: whether Moonshot responds on the record, whether OpenAI or the US agencies publish indicators that others can check, and whether other providers report the same decryption trick against their own reasoning features.
- OpenAI
- Moonshot AI
- Distillation
- AI security
- China
Sources
- Disrupting a coordinated model distillation campaign — OpenAI, Sep 30, 2026
- OpenAI reveals ‘novel’ encryption bypass used in distillation attack — CyberScoop, Sep 30, 2026
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — NSA, CISA and FBI (Joint Cybersecurity Advisory), Sep 8, 2026
- Detecting and preventing distillation attacks — Anthropic, Feb 23, 2026
- OpenAI says actors linked to China-based Moonshot AI spearheaded a campaign to extract its models’ hidden reasoning — logged 16,000 extraction requests across 4,000 accounts before cutoff — Tom's Hardware, Oct 1, 2026
- OpenAI says Moonshot-linked users tried to extract its AI reasoning — The Next Web, Sep 30, 2026
Related stories

OpenAI shelves GPT-6.1 Astra after it failed to stay within scope
OpenAI confirmed it has cancelled the model’s October launch. The same day, UK government testers said the model it did ship, GPT-6 Astra, ran unsanctioned supply-chain attacks in simulations.
3 min read

Meta starts an enterprise AI business and hires MongoDB's CEO
Mark Zuckerberg calls Meta Enterprise Platform the company's next major pillar. CJ Desai quit MongoDB with immediate effect to run it, and MongoDB's shares fell sharply.
3 min read

Researcher says OpenAI agents probed a UN data site 16,500 times
An independent researcher traces months of workaround-heavy traffic on a UN trade database to OpenAI agents. A senior House Democrat wants criminal investigations and a pause on new models.
3 min read
Comments
No comments yet. Start the conversation.