Menu Close

OpenAI says it disrupted July distillation campaign, attributes core cluster to Moonshot AI

Illustration on a bone-parchment background. On the left, an ember-copper bar chart labeled "EXTRACTION SPIKE" peaks sharply then drops under a diagonal "DISRUPTED" stamp, with no numerals on the axes. In the center, a sealed cobalt-steel capsule labeled "REASONING" sits behind a frost-teal lock ring tagged "PROTECTED REASONING LOCK". On the right, a fan of blank unbranded account tokens is crossed by a charcoal strap reading "CLUSTER CUT", tagged "ACCOUNT CLUSTER CUT". Quiet lower chips read "JULY SPIKE", "ATTEMPTED REQUESTS", "CORE CLUSTER", and "FMF SHARED".

OpenAI said Wednesday it identified and disrupted a coordinated July campaign to extract protected reasoning from its models, activity it called consistent with adversarial distillation, and attributed a core operator cluster to individuals associated with China’s Moonshot AI, the developer of Kimi.

In a company post, OpenAI said the earliest observed activity began July 1, with high-volume spikes on July 24 and 25 consisting of 16,000 requests using a relevant extraction pattern from over 4,000 users. Further investigation found related prompt-pattern activity across a cluster of more than 15,000 users, which OpenAI said it fully disrupted by July 28. A footnote states those figures describe attempted, not necessarily successful, extractions. Bloomberg Law reported that OpenAI accused Moonshot of a wide-scale effort to extract data from its GPT systems that could help reproduce the reasoning and capabilities of its most advanced models, with coordinated efforts beginning in early July and peaking at 16,000 requests later in the month.

OpenAI said operators did not break encryption, compromise a database, or gain direct access to stored user conversations. Instead, it said they manipulated model interactions so protected reasoning could be reproduced in forms visible to the requester, in a coordinated, scaled manner that violated its terms of service. “It is unclear whether all operators we observed during the relevant time period originated from a single actor,” OpenAI wrote. “However, we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi.” Neither OpenAI’s post nor the readable Bloomberg Law lede quotes a Moonshot response.

OpenAI said it banned or restricted fraudulent accounts, strengthened signup and infrastructure controls, expanded monitoring, and shared findings through the Frontier Model Forum and government channels. AI Tech Daily previously explained what distillation is and why China-linked labs would pursue frontier-model outputs. US agencies have also said Chinese AI firms ran industrial-scale model distillation campaigns.

Sources

0 0 votes
Article Rating
Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x