OpenAI said on September 30, 2026 that it had disrupted a coordinated model-distillation campaign aimed at extracting hidden model reasoning, and that it attributes “a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi.” The attribution is OpenAI’s own; the post describes the activity as “attempted, not necessarily successful, extractions.”
On this page
What OpenAI says happened
According to OpenAI, the activity began on July 1 at low volume. The company then observed “high-volume spikes on July 24 and 25 consisting of 16,000 requests using a relevant extraction pattern from over 4,000 users.” A wider investigation found related prompt-pattern activity across “a cluster of more than 15,000 users,” which OpenAI says it “fully disrupted by July 28.”
| Item | Figure, per OpenAI |
|---|---|
| Activity began | July 1, 2026 |
| Spike dates | July 24–25, 2026 |
| Requests with the extraction pattern in the spike | 16,000 |
| Users behind those requests | More than 4,000 |
| Wider related cluster | More than 15,000 users |
| Disrupted by | July 28, 2026 |
The method
OpenAI says the operators attempted extraction “by copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe the hidden reasoning content.” In other words, the model itself was asked to reveal reasoning that is otherwise kept encrypted.
OpenAI explains why it treats this as a safety issue and not only a commercial one: “Extracted reasoning could be used to train another model without preserving the safeguards applied to the original model’s user-facing outputs.” The company says the concern applies across the industry, not only to OpenAI.
OpenAI’s response
The post lists the following measures:
- banning or restricting the accounts involved;
- “strengthened signup and infrastructure controls, and expanded monitoring for related networks”;
- closing “a pathway that allowed someone who already possessed another user’s encrypted reasoning to replay it and recover its contents”;
- sharing relevant findings through the Frontier Model Forum and “appropriate government information-sharing channels.”
Why it matters
The account bans address the users OpenAI identified; the closed replay pathway changes how encrypted reasoning can be used across conversations, which applies to any account. By routing its findings through the Frontier Model Forum, OpenAI is passing the extraction pattern to other labs that offer reasoning models, consistent with its point that the risk is industry-wide.
Moonshot’s and OpenAI’s model line-ups by release date are tracked in the AI model release timeline; company profiles are in AI companies.




