OpenAI published an account on 30 September of what it calls a coordinated adversarial distillation campaign against its models, and attributed a core cluster of the activity to individuals associated with Moonshot AI, the Chinese lab behind Kimi.
OpenAI defines adversarial distillation as “the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model”. The technique it describes is pointed: operators copied encrypted reasoning out of one conversation, then asked a model in a separate conversation to decrypt and transcribe the hidden content.
By OpenAI’s account the activity began at low volume on 1 July 2026, spiked on 24 and 25 July with 16,000 requests from more than 4,000 users, and touched more than 15,000 users before being disrupted by 28 July. OpenAI says it banned or restricted accounts, tightened signup and infrastructure controls, and strengthened protections for hidden reasoning.
Two things the post does not say. OpenAI states that attribution for all the operators is not clear, and it does not claim any particular Moonshot model was trained on the extracted material, despite press framing to that effect. Moonshot had not responded publicly at the time of writing.
What makes this notable is the asset: the contested material is reasoning traces a lab deliberately hides, rather than training data or weights.
