<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/openai-says-moonshot-linked-users-tried-to-extract-its-ai-reasoning-mawfpamac" -->

---
title: OpenAI says Moonshot-linked users tried to extract its...
description: OpenAI reported shutting down a coordinated campaign in July that used thousands of accounts to extract hidden reasoning from its models, which it says was...
canonical: https://daily.dev/posts/openai-says-moonshot-linked-users-tried-to-extract-its-ai-reasoning-mawfpamac
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: OpenAI says Moonshot-linked users tried to extract its AI reasoning | daily.dev
og:description: OpenAI reported shutting down a coordinated campaign in July that used thousands of accounts to extract hidden reasoning from its models, which it says was...
og:url: https://daily.dev/posts/openai-says-moonshot-linked-users-tried-to-extract-its-ai-reasoning-mawfpamac
og:image: https://api.daily.dev/og/posts/maWFPamAc.png
og:image:alt: OpenAI says Moonshot-linked users tried to extract its AI reasoning
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenAI says Moonshot-linked users tried to extract its AI reasoning

**[The Next Web](https://daily.dev/sources/tnw)** · 2 min read · 0 upvotes · 0 comments

## Summary

OpenAI reported shutting down a coordinated campaign in July that used thousands of accounts to extract hidden reasoning from its models, which it says was linked to people associated with Chinese AI firm Moonshot (maker of Kimi). Requests spiked to 16,000 from over 4,000 users on July 24-25, with related activity across 15,000+ users before OpenAI shut it down by July 28. Operators reportedly asked one model to decrypt and transcribe encrypted reasoning copied from another conversation, a technique consistent with adversarial distillation. OpenAI says no encryption was broken and no user data was accessed; it has banned accounts, tightened sign-up checks, and shared findings with other labs and government agencies. The accusation follows a similar claim by Anthropic and a US government advisory naming six Chinese firms, which China has rejected; critics like David Sacks argue such claims are aimed at justifying bans on rival open models.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/openai-moonshot-distillation-campaign-hidden-reasoning>

## Questions this post answers

### How did the attackers extract OpenAI's hidden model reasoning without breaking encryption?

Operators copied encrypted reasoning output from one conversation and then asked a model in a separate conversation to decrypt and transcribe it, rather than breaking the encryption itself or accessing a database. OpenAI says no stored user conversations were reached. The technique is described as adversarial distillation, using another model's reasoning to help train or improve a competing model.

_Developers weighing AI vendor trust can follow how these security disputes unfold on daily.dev._

### What did OpenAI do after discovering the Moonshot-linked distillation campaign in July?

OpenAI banned the accounts involved, tightened sign-up verification checks, and added new protections for hidden reasoning output. The campaign ran from July 1 at low volume, spiked to 16,000 requests from over 4,000 users on July 24-25, and was fully shut down by July 28 after OpenAI traced related activity across more than 15,000 users.

_Teams building on AI APIs can track how providers respond to abuse incidents via daily.dev._

## Similar posts on daily.dev

- [Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI](https://daily.dev/posts/anthropic-accuses-alibaba-of-using-25-000-fake-accounts-to-scrape-claude-ai-wxxhratg1) · InfoWorld · 1 upvotes · 0 comments

---

Tags: [#machine-learning](https://daily.dev/tags/machine-learning), [#llm](https://daily.dev/tags/llm), [#openai](https://daily.dev/tags/openai), [#ai-security](https://daily.dev/tags/ai-security), [#moonshot-ai](https://daily.dev/tags/moonshot-ai)

[View this post on daily.dev](https://daily.dev/posts/openai-says-moonshot-linked-users-tried-to-extract-its-ai-reasoning-mawfpamac)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"OpenAI says Moonshot-linked users tried to extract its AI reasoning","url":"https://daily.dev/posts/openai-says-moonshot-linked-users-tried-to-extract-its-ai-reasoning-mawfpamac","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/openai-says-moonshot-linked-users-tried-to-extract-its-ai-reasoning-mawfpamac"},"datePublished":"2026-09-30T17:56:34.965Z","dateModified":"2026-10-01T07:16:58.236Z","description":"OpenAI reported shutting down a coordinated campaign in July that used thousands of accounts to extract hidden reasoning from its models, which it says was...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d190083211b8a9dcfd3443c0f0e29c12?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d190083211b8a9dcfd3443c0f0e29c12?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Next Web","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Next Web","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tnw","url":"https://daily.dev/sources/tnw"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/openai-says-moonshot-linked-users-tried-to-extract-its-ai-reasoning-mawfpamac","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"machine-learning,llm,openai,ai-security,moonshot-ai","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Next Web","item":"https://daily.dev/sources/tnw"},{"@type":"ListItem","position":3,"name":"OpenAI says Moonshot-linked users tried to extract its AI reasoning"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/openai-says-moonshot-linked-users-tried-to-extract-its-ai-reasoning-mawfpamac#faq","mainEntity":[{"@type":"Question","name":"How did the attackers extract OpenAI's hidden model reasoning without breaking encryption?","acceptedAnswer":{"@type":"Answer","text":"Operators copied encrypted reasoning output from one conversation and then asked a model in a separate conversation to decrypt and transcribe it, rather than breaking the encryption itself or accessing a database. OpenAI says no stored user conversations were reached. The technique is described as adversarial distillation, using another model's reasoning to help train or improve a competing model. Developers weighing AI vendor trust can follow how these security disputes unfold on daily.dev."}},{"@type":"Question","name":"What did OpenAI do after discovering the Moonshot-linked distillation campaign in July?","acceptedAnswer":{"@type":"Answer","text":"OpenAI banned the accounts involved, tightened sign-up verification checks, and added new protections for hidden reasoning output. The campaign ran from July 1 at low volume, spiked to 16,000 requests from over 4,000 users on July 24-25, and was fully shut down by July 28 after OpenAI traced related activity across more than 15,000 users. Teams building on AI APIs can track how providers respond to abuse incidents via daily.dev."}}]}
```

