Editorial illustration for OpenAI Links Stolen Model Attempts to China's Moonshot AI
OpenAI Blames China's Moonshot AI for Model Theft
OpenAI Links Stolen Model Attempts to China's Moonshot AI
OpenAI says it caught thousands of accounts trying to copy the reasoning steps that sit behind its models' answers, and it's pointing a finger at people tied to Moonshot AI, the Chinese company behind the Kimi language model. The company laid out the episode in a blog post, describing a campaign that started small on July 1 and ballooned to 16,000 requests from more than 4,000 users within a single weekend in late July. OpenAI says it traced the pattern to a network of over 15,000 accounts and shut the whole thing down by July 28.
The target wasn't the final answer a chatbot spits out. It was the hidden chain of thought that produces it, the intermediate reasoning most users never see. OpenAI says that reasoning sometimes carries information the company deliberately keeps out of the visible answer, which is part of why losing control of it matters. Copying those chains, a technique known as distillation, lets a rival model learn to mimic a stronger one's problem-solving without actually building that capability from scratch.
OpenAI says it stopped the activity on its own platform. But according to the company, the same extraction method kept working elsewhere, including on Microsoft's Azure OpenAI service, for weeks afterward.
Why this matters
Reasoning traces are becoming the thing worth stealing in this industry, not just weights. OpenAI's footnote admitting these were "attempted" extractions, not confirmed thefts, tells us the company is still working out how to measure this kind of theft at all. That's a problem for anyone building on top of frontier models: if the provider can't say with confidence whether its chain-of-thought got copied, how do downstream developers assess what they're actually licensing?
The Azure detail is the real story for builders. OpenAI says it caught and stopped the campaign on its own infrastructure, but the same technique kept working on Microsoft's cloud for weeks. That's not a flaw in one company's defenses, it's a reminder that model security is only as strong as the weakest platform serving the model. If you're deploying through a third-party cloud, ask who's actually watching for distillation attempts.
The Moonshot AI link deserves skepticism until OpenAI shows more than attribution by association. Naming a "core group" tied to Kimi's maker is a serious claim. Watch for whether OpenAI publishes evidence, or whether this stays a blog-post accusation.
Common Questions Answered
What was the scale of the attempted model theft campaign that OpenAI linked to Moonshot AI?
OpenAI detected a coordinated campaign involving over 15,000 accounts and more than 4,000 users that attempted to copy the reasoning steps behind its models' answers. The campaign started on July 1 and escalated dramatically to 16,000 requests within a single weekend in late July, demonstrating a significant and rapidly growing theft attempt.
Why are reasoning traces becoming a valuable target for AI model theft according to the article?
Reasoning traces, which represent the hidden chain-of-thought processes behind AI model answers, are increasingly becoming the primary focus of theft rather than just model weights. This shift indicates that the industry recognizes the strategic value of understanding how frontier models arrive at their conclusions, making these reasoning steps a high-priority target for competitors.
What vulnerability did researchers discover regarding OpenAI's security on cloud platforms?
Researchers found that the same technique used to extract reasoning steps continued to work for weeks on cloud platforms like Microsoft Azure, even after OpenAI claimed to have broken up the coordinated campaign. This suggests that the vulnerability persisted across multiple cloud infrastructure providers despite OpenAI's intervention efforts.
What challenge does OpenAI's uncertainty about model theft pose for downstream developers?
OpenAI's admission that these were 'attempted' extractions rather than confirmed thefts reveals the company is still developing methods to measure and detect this type of intellectual property theft. This uncertainty creates problems for developers building on top of frontier models, as they cannot confidently assess whether the chain-of-thought reasoning they are licensing has been compromised or stolen.
Further Reading
- OpenAI links China's Moonshot AI to extraction attempt - CNBC
- OpenAI reveals ‘novel’ encryption bypass used in distillation attack - CyberScoop
- OpenAI Accuses Moonshot AI of Coordinated Model Distillation - BankInfoSecurity
- OpenAI links large-scale reasoning extraction campaign to Moonshot AI - CityBiz
- OpenAI says Moonshot-linked users tried to extract its AI reasoning - The Next Web