1 min read

OpenAI Links Moonshot AI Associates to Reasoning-Extraction Campaign

The activity peaked at 16,000 attempted requests from more than 4,000 users on July 24 and 25. OpenAI said it disrupted the broader activity by July 28.

Two smartphones display blurred encrypted blocks beside a closed padlock / TokenPost.ai
Two smartphones display blurred encrypted blocks beside a closed padlock / TokenPost.ai

OpenAI said Sept. 30 that it disrupted a coordinated campaign to extract protected reasoning from its models, attributing a core cluster to individuals associated with Moonshot AI, the developer of Kimi.

The activity began July 1 and surged July 24 and 25, when more than 4,000 users generated 16,000 requests matching an extraction pattern. OpenAI said the figures represent attempted, not necessarily successful, extractions. A broader investigation found related prompt activity across a cluster of more than 15,000 users, which the company said it fully disrupted by July 28.

OpenAI described the activity as adversarial distillation, a method that uses one model’s outputs or reasoning to train, reproduce or improve another model. One technique involved copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe it.

The operators did not break encryption, compromise a database or directly access stored user conversations, OpenAI said. Instead, they manipulated model interactions to make protected reasoning visible to requesters.

OpenAI banned or restricted fraudulent accounts, strengthened signup and infrastructure controls, and expanded monitoring. It also closed a replay pathway involving encrypted reasoning and shared findings with industry and government partners. The company said it expects such attempts to become more sophisticated as frontier models advance.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…