OpenAI said on September 30 that it had identified and dismantled an organized model-distillation operation aimed at extracting protected reasoning content from its reasoning models. The company tied the activity of one "core cluster" to people working for Moonshot AI. Moonshot AI did not respond to CyberScoop's request for comment.
From July 1 to July 28
According to the timeline OpenAI disclosed:
- July 1: low-level suspicious activity was first detected, and it gradually increased from there;
- July 24-25: roughly 4,000 users sent about 16,000 prompts matching the same extraction pattern;
- July 28: the number of suspicious users grew to about 15,000, and OpenAI said it "fully dismantled" the operation that day.
On method, OpenAI said the group did not break any encryption, did not breach any database, and never obtained stored user conversations. Instead, they manipulated model interactions so that reasoning content meant to stay hidden was recited back in a form visible to the requester. CyberScoop described one technique as a "novel encryption bypass": copying encrypted reasoning data out of one session, then feeding it into a separate session and asking the model to decrypt and transcribe it into plain text.
"They manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester."
OpenAI's response included banning the accounts, tightening sign-up and infrastructure controls, expanding network monitoring, and patching the flaw that allowed cross-session decryption. The findings were shared through the Frontier Model Forum and government channels. OpenAI said that once reasoning content is extracted, it can be used to train derivative models that lack the original model's safety measures, creating both safety and national-security risks.
Attribution in a Single Sentence
CyberScoop pointed out that OpenAI's blog post offered no technical evidence or reasoning chain for tying the activity to Moonshot AI. The wording was "individuals working on behalf of Moonshot AI" — the post never clarifies whether this means individual actors or company-directed conduct. Based on what has been made public so far, outside observers cannot independently verify the attribution.
Over the past several months, U.S. officials have repeatedly and publicly accused Chinese companies of distilling American models, and the White House's science adviser has made similar remarks. What is different this time is that OpenAI gave specific dates, user counts, and attack methods, and named a Chinese company valued in the tens of billions of dollars directly in the body of its post.
Another Story the Same Week
The accusation landed the same week Kimi K3 walked straight into OpenAI's enterprise sales pipeline. U.S. inference provider Baseten now hosts Kimi K3, and enterprise customers can call it directly inside Codex, with the spend counted against purchase commitments they have already signed with OpenAI — no separate vendor contract required. It is being seen as the first time a Chinese open-source model has entered OpenAI's enterprise billing system. Baseten's Philip Kiely wrote that enterprise teams can now natively use open-source models like GLM-5.3 Flash and Kimi K3 inside Codex. Codex lead Tibo reposted the news with a single line: "Open is the way."
For domestic model companies and the developers tracking them, the two stories read as more informative taken together. Open weights let Kimi K3 sidestep export and procurement hurdles by being hosted by a U.S. company and sold to U.S. enterprises — and that same company is now named by OpenAI as linked to a distillation operation. Whether overseas buyers face extra compliance scrutiny as a result depends on whether more evidence surfaces later.
OpenAI did not say whether the accusation affects Kimi K3's availability inside Codex, and neither Baseten nor Moonshot AI has commented on the matter.
Sources: OpenAI's official blog, CyberScoop, TechNode, CocoLoop; suspicious-user and prompt counts follow OpenAI's disclosure, and Codex enterprise billing details follow Baseten's statements.