Today ainotis

Policy1 Oct 2026That day's edition

Running case: OpenAI's models 8 stories

OpenAI disrupted a distillation campaign it partly ties to Moonshot

OpenAI says a coordinated campaign tried to extract protected reasoning from its models from 1 July, and it attributes a core cluster to individuals associated with Moonshot AI.

Check our sources · 1 source, 8 claims

Key points

  1. OpenAI says activity began on 1 July, with spikes on 24 and 25 July of 16,000 requests from over 4,000 users, which it describes as attempted, not necessarily successful, extractions.
  2. OpenAI says activity across more than 15,000 users was fully disrupted by 28 July, and operators did not break its encryption or gain direct access to stored user conversations.
  3. OpenAI says it is unclear whether one actor was behind it, attributes a core cluster to individuals associated with Moonshot AI, and closed a pathway for replaying encrypted reasoning.

What happened

OpenAI published a post on 30 September 2026 about a coordinated campaign to extract protected reasoning from its models. It says activity began on 1 July and spiked on 24 and 25 July with 16,000 requests from over 4,000 users. It says related prompt-pattern activity across more than 15,000 users was fully disrupted by 28 July.

OpenAI says it is unclear whether all operators came from a single actor, and attributes a core cluster to individuals associated with Moonshot AI, the developer of Kimi.

OpenAI says it banned or restricted fraudulent accounts, closed a pathway for replaying another user’s encrypted reasoning, and shared findings through the Frontier Model Forum.

What it means for you

Our view

This is OpenAI’s account, and the attribution to Moonshot AI is its own. The post says it is unclear whether one actor was responsible, and the 16,000 requests were attempted extractions that may not have succeeded.

For teams that use hosted reasoning models, the useful detail is what OpenAI says it changed: stronger signup and infrastructure controls, and a closed pathway for replaying another user’s encrypted reasoning.

If you build on a provider’s reasoning outputs, ask which abuse controls cover your own accounts and whether the provider will tell you when a pathway like this is closed.

This part is our reading of the facts above. It adds no fact of its own.

Your reaction

One press adds one. We count a number for each notice and day, never who pressed it.

Check our sources

1 source, 8 claims. We opened the source and checked every sentence above against it.

1 Disrupting a coordinated model-distillation campaignOpenAI · 30 Sep 2026 · 8 claims Open the source
  1. OpenAI published Disrupting a coordinated model-distillation campaign on 30 September 2026.

    Disrupting a coordinated model-distillation campaign
  2. OpenAI says the campaign was designed to extract protected reasoning from its models, with the earliest observed activity in the first week of July.

    We recently identified and disrupted a coordinated campaign designed to extract protected reasoning from our models, with the earliest observed activity occurring in the first week of July.
  3. OpenAI says the activity began on July 1 and had high-volume spikes on July 24 and 25 of 16,000 requests from over 4,000 users using a relevant extraction pattern; it says these were attempted, not necessarily successful, extractions.

    Narrowed to what the source supports
    The activity began on July 1, initially at a low volume until we observed high-volume spikes on July 24 and 25 consisting of 16,000 requests1 using a relevant extraction pattern from over 4,000 users.
  4. OpenAI says related prompt-pattern activity across a cluster of more than 15,000 users was fully disrupted by July 28.

    Further investigation identified related prompt-pattern activity across a cluster of more than 15,000 users, which we fully disrupted by July 28.
  5. OpenAI says it is unclear whether all operators came from a single actor, but "we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi."

    It is unclear whether all operators we observed during the relevant time period originated from a single actor. However, we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi.
  6. OpenAI says the operators did not break its encryption, compromise a database, or gain direct access to stored user conversations.

    The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations.
  7. OpenAI says it banned or restricted fraudulent accounts, strengthened signup and infrastructure controls, and closed a pathway that allowed someone who already possessed another user’s encrypted reasoning to replay it and recover its contents.

    We banned or restricted fraudulent accounts, strengthened signup and infrastructure controls, and expanded monitoring for related networks.
  8. OpenAI says it shared information about the manipulation with industry partners through the Frontier Model Forum.

    we have shared information about it with industry partners through the Frontier Model Forum in order to strengthen collective defenses against adversarial distillation.

Nothing appears on this site that we have not opened and linked.

Filed under