OpenAI identified and disrupted a coordinated adversarial distillation campaign attributed to individuals associated with Moonshot AI, the developer of Kimi. The operators manipulated model interactions to extract protected internal reasoning from OpenAI models in violation of terms of service.

  • Activity began on July 1, escalating to high-volume spikes of 16,000 requests from over 4,000 users on July 24 and 25.
  • Related prompt-pattern activity was identified across a cluster of more than 15,000 users, fully disrupted by July 28.
  • Attackers attempted to extract reasoning by copying encrypted content from one conversation and asking a model in another to decrypt it.
  • OpenAI mitigated the campaign through account enforcement, technical controls, and coordination with the Frontier Model Forum.

The company warns that adversarial distillation poses safety and national security risks by allowing others to reproduce model capabilities without preserving original safeguards.