The Information Machine
Following·Day 227·first covered 23 Feb 2026·10 sources

OpenAI Attributes Summer Distillation Campaign to Moonshot AI Associates

The gist

The attack demonstrated a technique OpenAI described as novel, capable of reproducing protected model reasoning without breaching encryption, and OpenAI said the same vulnerability is present in other frontier AI systems. The Frontier Model Forum has identified adversarial distillation as a dedicated frontier-model security issue, with mathematical and scientific reasoning capabilities flagged as key targets due to their relevance to CBRN domains.

The full picture

OpenAI disclosed it detected and disrupted a coordinated campaign to extract protected reasoning from its models, attributing a core cluster of the activity to individuals associated with Moonshot AI, the Beijing-based developer of Kimi. The attack began in the first week of July, peaked at 16,000 requests from more than 4,000 users on July 24-25, and was fully shut down by July 28. Attackers did not break encryption or access databases; instead they copied encrypted reasoning from one conversation and asked the model in a separate conversation to transcribe it, reproducing protected content in readable form. OpenAI deployed additional mitigations, banned the fraudulent accounts, and shared findings with industry partners through the Frontier Model Forum and with government information-sharing channels. Moonshot AI had not issued any public statement as of early October. OpenAI explicitly framed adversarial distillation as a national security concern, arguing that capability transfer without matching safety investment is especially dangerous in dual-use domains. The 16,000-request incident is smaller in scale than distillation attempts reported by Anthropic, which logged incidents in the millions of exchanges. OpenAI and Microsoft previously raised similar concerns about DeepSeek in early 2025. China's government has previously rejected distillation accusations from U.S. companies and the Trump administration and has threatened retaliation against U.S. penalties.

How it developed
3 October 2026

Moonshot AI had still issued no public statement or denial as of this date

30 September 2026

OpenAI publicly disclosed the distillation campaign and attributed it to individuals associated with Moonshot AI

23 February 2026

Frontier Model Forum published an issue brief identifying adversarial distillation as a growing frontier AI safety and security concern

Sources
5 more sources
The daily email

Want this in your inbox?

I send one email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free