Skip to content
RegionAsia-Pacific

MediumV Technology Geopolitics & AI30 September 2026, Wednesday

OpenAI links hidden-reasoning extraction campaign to China's Moonshot AI

OpenAI said on 30 September that it had disrupted a campaign to extract its models' hidden reasoning traces. The company tied a core cluster of 16,000 requests from more than 4,000 users on 24–25 July to people linked to Beijing-based Moonshot AI.

Location: BEIJING

According to OpenAI, the activity began at low volume on 1 July, peaked on 24–25 July and was fully halted on 28 July. The company identified more than 15,000 users employing similar request patterns. The method involved copying an encrypted reasoning trace from one conversation and asking the model in a 2nd conversation to transcribe it. OpenAI says the attackers neither broke the encryption nor accessed its databases. The weakness lay in encrypted traces being interchangeable between 2 different sessions or models.

OpenAI calls this 'adversarial distillation': using one model's output without permission to train a rival model. According to The Hacker News on 1 October, the company did not publish technical evidence for the attribution. According to Wccftech, White House science adviser Michael Kratsios said in late July that the US government had information that Moonshot had distilled its Kimi K3 model from Anthropic models. None of the 3 sources carried a response from Moonshot AI, and none could be verified.

About 2 months passed between halting the campaign and disclosing it. According to Resultsense on 1 October, the disclosure coincided with a period in which Moonshot was conducting an internal review after a separate security incident involving its Kimi models.

Talay assessment

Bottom line

The disclosure shows US–China AI rivalry shifting from chip exports to model outputs. Following the White House allegation in late July, a US lab has now targeted a single Chinese company with concrete figures. The most likely outcome is that distillation moves into export control or sanctions files, though the lack of public technical evidence could slow legal action.

Likely effects

  • Chinese AI companiesNegative1–6 months

    Firms such as Moonshot face the risk of Entity List designation or service restrictions on their access to US cloud and APIs.

  • US model providersUncertainWeeks

    The revelation that reasoning traces can be carried between sessions pushes providers to redesign API security.

  • AI users in TürkiyeNegative1–6 months

    If US providers tighten identity checks and usage limits, access costs could rise for developers in third countries, Türkiye included.

Possibilities, ranked

  1. 1
    Formal restriction45%

    Washington turns the distillation allegations into listings or access restrictions aimed at Chinese AI companies.

    Watch: The Commerce Department adding Moonshot AI to the Entity List

  2. 2
    A dispute between companies40%

    The matter stays confined to providers' own safeguards and public statements.

    Watch: Other US labs publishing similar attribution reports

  3. 3
    Attribution weakens15%

    Moonshot rebuts the allegations with technical data and the issue fades.

    Watch: An official Moonshot AI statement containing a technical rebuttal

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Extraction requests at peak▼ 16,000
  • Users with similar patterns▼ 15,000+
  • Campaign duration▼ 28 days

Sources

  1. The Hacker News — OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI
  2. Wccftech — Moonshot AI tried to crack OpenAI's encrypted reasoning through 16,000 requests
  3. Resultsense — OpenAI links model-distillation campaign to Moonshot AI