OpenAI disclosed that it detected and suspended an organized operation focused on extracting protected reasoning functionalities from its artificial intelligence systems. The company attributed a significant part of this activity to individuals linked to Moonshot AI, the developer of the Kimi chatbot.
This activity began in early July and peaked between the 24th and 25th of the same month. During this period, OpenAI registered 16,000 requests from over four thousand users following a similar extraction pattern. Later, the investigation revealed connections with more than 15,000 users. The campaign was completely halted by the company on July 28th.
It is important to note that model distillation is a legitimate training methodology, where a more powerful system, called the 'teacher,' generates responses used to instruct a secondary model, the 'student.' The purpose of this technique is to develop smaller and more economical systems capable of replicating certain capabilities of the main model without requiring the same level of processing.
The controversy arises when corporations use third-party proprietary models to collect large volumes of responses without permission, aiming to reproduce capabilities considered protected. In this scenario, American AI companies have begun referring to such actions as illicit distillation.
The intermediate reasoning of the models gained prominence in this process. Instead of just capturing final answers, a distillation operation can seek information on how a system solves complex problems, providing the training model with more detailed examples of the path to a specific conclusion.
This accusation by OpenAI occurs within a broader dispute between Chinese companies and American AI laboratories. In February, Anthropic reported identifying distillation campaigns involving three Chinese labs, including Moonshot. At that time, Anthropic mentioned finding over 16 million interactions with Claude linked to about 24,000 fake accounts, with Moonshot being responsible for over 3.4 million of these interactions.
In September, Anthropic reiterated the accusation against Moonshot for using its models for training purposes. A company report indicated that the startup discreetly sent requests from its own clients to Claude, causing users who thought they were using Kimi to receive responses from the Anthropic model. Anthropic identified nearly 300,000 requests directed to Claude over a ten-day period, mainly for the Opus model, using a network composed of 5,380 fraudulent accounts. Furthermore, Anthropic pointed out mechanisms created to extract reasoning logs from the obtained responses.
According to Anthropic, Moonshot observed over 23 million interactions related to distillation campaigns between May and July 2026, although this data refers to Anthropic's internal investigations and not the current campaign reported by OpenAI.
Discussion reaches the United States government
The issue also reached the governmental sphere of the United States. In July, Treasury Secretary Scott Bessent stated that the government could impose sanctions on open-source Chinese models if evidence of American model distillation was confirmed. At that time, Bessent stated that US authorities were locating signatures associated with major US language models in various Chinese models, classifying the situation as unacceptable.
The possibility of sanctions arose amid allegations that Chinese companies were using American models to accelerate the development of their own systems. Reuters reported at the time that US authorities were also examining possible restrictions against Chinese companies, while Beijing refuted the accusations of misappropriation of technology.
For its part, Moonshot had previously denied the claim that the performance of its Kimi K3 model resulted from distillation. According to Reuters, the company alleged that the performance advancements were achieved through internal modifications to the system architecture.
OpenAI clarifies that the incident does not constitute an exclusive failure of its models. The company shared details of the campaign with industry partners through the Frontier Model Forum, with the aim of strengthening defenses against similar attempts. In addition to blocking the involved accounts, the company reinforced account creation and infrastructure controls, expanded network monitoring, and corrected the feature that allowed transferring encrypted reasoning data from one conversation to another and attempting to decipher it again into readable text.
The organization predicts that this type of operation will become increasingly complex as cutting-edge models evolve. OpenAI stated: 'We expect adversarial distillation attempts to become more sophisticated as frontier models improve and agents seek cheaper ways to replicate their capabilities. Defending against this activity requires multi-layered controls and continuous adaptation.'

