OpenAI accused Moonshot AI, the Chinese firm developing the Kimi model, of being linked to a campaign to distill its artificial intelligence systems. According to the report from the American company, this operation would have included more than 10,000 attacks aimed at extracting information about the internal reasoning of ChatGPT and other models.
The campaign is said to have started on July 1, 2026, and peaked between the 24th and 25th of that same month. OpenAI claims it was able to definitively interrupt those activities a few days later. Although it did not attribute all operations to a single responsible party, it identified a core of activity related to individuals linked to Moonshot AI.
The episode brings the focus back to the distillation of artificial intelligence models, a technique that allows for the creation of more economical and efficient systems based on the capabilities of others. However, its unauthorized use generates strong tensions among the leading companies in the sector.
According to the report, the attacks aimed to obtain protected data about the functioning of language models, including the reasoning processes that allow for solving complex problems. To achieve this, the alleged perpetrators would have employed novel distillation methods designed to extract those capabilities.
How the extraction campaign developed
OpenAI believes that these techniques could become more sophisticated with the advancement of artificial intelligence. Therefore, it warned about the difficulties in identifying and stopping operations of this scale, especially when different access methods are combined.
The company clarified that the incident did not compromise its databases, encryption systems, or other internal infrastructures. The activity would have focused on obtaining responses from the models to use them in the training of other systems, without directly accessing the servers or stealing stored information.













