OpenAI said it disrupted a coordinated model-distillation campaign in July that it primarily attributed to a cluster associated with Chinese AI developer Moonshot AI, creator of Kimi. The alleged operation used coordinated, high-volume prompts to extract protected model reasoning exposed to requesters, rather than accessing encrypted systems, databases, or user conversations. OpenAI reported approximately 16,000 extraction-pattern requests from more than 4,000 users on July 24–25, with related prompt activity spanning over 15,000 users.
OpenAI said it banned accounts involved in the activity on July 28, strengthened monitoring and controls, and closed a replay pathway involving encrypted reasoning. The company shared investigative details with industry and government information-sharing groups. The reported activity highlights the risk that sophisticated adversaries may seek to replicate proprietary model capabilities through API-driven extraction rather than conventional network intrusion.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
OpenAI said it fully disrupted the campaign on July 28 and banned accounts involved in the model-copying activity. It attributed the core cluster to Moonshot AI, developer of Kimi, while stating it could not establish that every observed operator was tied to one rival company.
OpenAI observed 16,000 requests using a relevant extraction pattern from more than 4,000 users across July 24 and 25. It also identified related prompt-pattern activity involving more than 15,000 users.
OpenAI reported that an adversarial model-distillation campaign began on July 1, manipulating model interactions to reproduce protected reasoning in requester-visible forms. The company said the activity did not involve breaking encryption, compromising databases, or directly accessing stored user conversations.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.