OpenAI's Moonshot distillation claim: what it alleges
OpenAI says people tied to Moonshot AI, maker of Kimi, tried to copy its hidden reasoning. What the distillation claim alleges, what's proven, and what's not.
Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

OpenAI says operators it ties to China's Moonshot AI, the company behind the Kimi models, ran a coordinated campaign this summer to pull the hidden reasoning out of its models and use it to train their own. OpenAI made the claim in a post on September 30, 2026. This OpenAI Moonshot distillation claim comes from a direct competitor, it has not been tested by any court or regulator, and OpenAI published no technical evidence for who was behind it. Here is what OpenAI alleges, what outside work backs up, and what Moonshot has said.
Key takeaways
- OpenAI's claim: the activity began July 1, 2026, peaked on July 24 and 25 with 16,000 requests from more than 4,000 users, and was fully shut down by July 28. OpenAI links a "core cluster" of the operators to Moonshot AI.
- Not a hack, OpenAI says: the operators did not break its encryption, get into a database or reach stored user conversations. They tricked its models into revealing reasoning that is normally hidden.
- The method is real: independent researchers showed in August that this kind of reasoning leak worked against OpenAI, Anthropic and Google. That proves the hole existed, not who used it.
- The attribution is unproven: OpenAI cited no technical evidence for the Moonshot link, and no court or regulator has found that Moonshot did anything.
- Moonshot's side: as of October 1, 2026, we found no public response from Moonshot to OpenAI's claim.
What the OpenAI Moonshot distillation claim alleges
Everything in this section is OpenAI's account. According to The Hacker News' summary of the post, the activity started on July 1, 2026 at low volume, then spiked on July 24 and 25 to 16,000 requests using one extraction pattern, sent by more than 4,000 users. Looking wider, OpenAI found the same prompt pattern across more than 15,000 users, and says it had fully disrupted the campaign by July 28.
OpenAI says it "strongly believes" a core cluster of the operators is associated with Moonshot AI, as BankInfoSecurity reported. It also says it isn't sure every account belonged to one coordinated effort. That matters: the 4,000 and 15,000 figures count users who sent a similar prompt, not accounts OpenAI has shown to be Moonshot's.
| Date (2026) | What OpenAI says happened |
|---|---|
| July 1 | Extraction activity begins, at low volume |
| July 24 and 25 | 16,000 requests from more than 4,000 users |
| By July 28 | Campaign fully disrupted; related pattern seen across 15,000+ users |
| September 30 | OpenAI publishes its account |
How the hidden reasoning was extracted
Reasoning models work through a problem step by step before they answer. OpenAI doesn't show users that raw reasoning; it hands it back as an encrypted block so the model can pick up where it left off. OpenAI says the operators copied an encrypted block from one conversation, pasted it into another, and asked the model there to decrypt it and write it out.
OpenAI says it banned the accounts, closed the path that let encrypted reasoning be replayed, and added checks for streamed answers that expose reasoning. It also tightened sign-up controls and shared its findings through the Frontier Model Forum, an industry group, and government channels. OpenAI says the activity broke its terms of service; The Register reports OpenAI didn't say which models were targeted.
What adversarial distillation means in plain words
Distillation means training a new "student" model on the answers of a stronger "teacher" model. It's a normal technique when a company does it with its own models. OpenAI calls it "adversarial distillation" when someone does it to another company's model at scale, without permission.
The step-by-step reasoning is the prize because it shows how a strong model gets to an answer, not just the answer. OpenAI's argument, quoted by The Hacker News, is that a model trained on extracted reasoning could inherit the skill without the safeguards. OpenAI's Caroline Zier told Bloomberg, as quoted by The Next Web, that its concern is the terms-of-service violation, not open models or legitimate distillation.
What is independently verified, and what isn't
Verified by outside work: the weakness was real. OpenAI says it learned of it from independent researchers who were writing a paper. A paper matching that description, posted to arXiv on August 10, 2026, found that encrypted reasoning blocks could be swapped across sessions, users and models within the same provider. Its authors pulled hidden reasoning out of Anthropic, OpenAI and Google models this way.
Not verified: that Moonshot was behind it. The Hacker News notes OpenAI did not cite any technical evidence for the attribution. No court, regulator or independent researcher has confirmed it.
A second rival says something similar. Anthropic, which also competes with Moonshot, made its own accusation in its September 10 threat report. It says Moonshot quietly forwarded Kimi customers' requests to Claude, almost 300,000 of them in one ten-day period through 5,380 fraudulent accounts, and used a similar replay trick on Claude's reasoning. Two interested companies telling a similar story is worth noting. It is still two claims, not a finding. We covered another Anthropic report on a Chinese lab in our piece on GLM-5.3's exploit tests.
What Moonshot has said
As of October 1, 2026, we found no public statement from Moonshot AI on OpenAI's claim. The Register asked the company for comment and did not get an immediate reply.
Moonshot has not answered Anthropic's routing claim directly either. A September 12 statement, reported by BeInCrypto, called online rumors about its founder and employees fabricated and said it had gone to the police. That statement did not address the Claude routing allegation.
Why it matters if you use Kimi

For now, nothing changes in how Kimi works. OpenAI's measures apply to accounts on its own platform, and its claim is about how Moonshot may have trained its models, not about Kimi users' data. If the claim holds up, the question it raises is whether some of Kimi's skill was built on copied reasoning.
The privacy question comes from Anthropic's separate claim: it says some forwarded requests held sensitive customer data, and it doesn't know whether Moonshot told customers. That is unproven too. Still, if you send business data to any hosted model, Kimi included, read the provider's data terms before you do.
What happens next
Watch for three things: a Moonshot response, any technical evidence OpenAI or other labs release, and government action. Keep the commercial stakes in mind too. OpenAI's models are what it is asking investors to value in its reported new funding round, which gives it every reason to defend them in public and gives you a reason to read its claims with care.
Bottom line
OpenAI claims Moonshot-linked operators used a real, independently documented weakness to copy its models' hidden reasoning in July. The weakness is proven. The OpenAI Moonshot distillation link is OpenAI's assertion, without published evidence, and Moonshot had not responded as of October 1, 2026. Treat it as a serious accusation from a rival, not a finding.
FAQ
What is AI model distillation?
It's training one model on the outputs of another, so the smaller or newer model learns to imitate the stronger one. Companies do it legitimately with their own models. OpenAI objects when it's done to its models without permission, against its terms of service.
Did Moonshot hack OpenAI?
Not by OpenAI's own account. OpenAI says the operators didn't break its encryption, compromise a database or reach stored user conversations. It says they misused normal access to make the models reveal reasoning that is meant to stay hidden.
Has Moonshot AI responded to OpenAI?
As of October 1, 2026, we found no public response. The Register asked Moonshot for comment and had no immediate reply.
Is it safe to keep using Kimi?
OpenAI's claim doesn't say Kimi users' data was exposed, and no regulator has acted against Moonshot. Anthropic's separate claim raises a privacy question about forwarded requests, which is unproven. Keep sensitive data out of any hosted chatbot unless you've read its data terms.