BREAKING
Technology

OpenAI Accuses Moonshot of Massive Campaign to Copy AI Models

has identified what it calls a coordinated campaign aimed at distilling the company’s AI models. Distillation refers to the process of using the outputs or reasoning of a larger AI model to train a smaller one. OpenAI alleges that this campaign was linked to individuals at Moonshot AI, the Chinese AI lab that launched the Kimi K3 model.

In a blog post, OpenAI explained that the campaign attempted to extract the protected reasoning of its AI models. Simply put, the campaign allegedly used prompts (instructions) to copy the way OpenAI’s models processed user queries.

It is unclear whether all the users involved in the campaign were linked to the same group. However, according to OpenAI, a “core” of the activity was associated with Moonshot AI. If confirmed, this could mean that Moonshot AI used OpenAI’s models to train its own future models. Notably, the Chinese lab launched the Kimi K3 model on July 16, 2026. Moonshot AI has not yet commented on these allegations.

How did this happen?

OpenAI added, however, that those responsible for the campaign “did not breach our encryption, compromise any databases, or gain direct access to stored user conversations.” According to the company, the campaign also attempted to copy the encoded reasoning from a conversation and ask a model in a separate conversation to decipher and transcribe the hidden content of that reasoning.

OpenAI maintains that this campaign likely began on July 1 of this year. On July 24 and 25, the company recorded up to 16,000 requests-originating from more than 4,000 users-that employed a specific extraction pattern. Subsequent investigation, according to OpenAI, revealed that over 15,000 users were utilising similar instructions. By July 28, the company had succeeded in completely neutralising the campaign. The campaign’s activity was observed to evolve over time, which, according to OpenAI, demonstrated that addressing this type of distillation required adaptive, layered defences.

What did OpenAI do?

In response to the campaign, OpenAI suspended or restricted the fraudulent accounts. The company states that it also strengthened registration controls and infrastructure, while expanding monitoring of related networks. When the associated activity occurred services, OpenAI collaborated with those providers to identify and disable the accounts involved.

According to OpenAI, this type of distillation campaign could allow an AI lab to equip its models with advanced capabilities without “requiring the same investment in safety.” This could prove problematic, especially at a time when AI safety is a subject of global debate.

This is not the first time a US AI lab has accused Chinese companies of attempting to distil its models. This revelation comes weeks after Anthropic accused several Chinese AI developers-including Moonshot AI and Alibaba-of secretly using its Claude models to help train their own systems.

More recently, three US agencies issued a joint cybersecurity alert alleging that Chinese AI companies had been extracting capabilities from cutting-edge US models, including GPT (OpenAI), Claude (Anthropic), Gemini (Google), and Grok. Earlier this month, China rejected these accusations, and its Ministry of Foreign Affairs urged the United States to “refrain from making unfounded or defamatory accusations.”