
OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China's Moonshot AI of being involved in a "distillation attack" that began July 1. The house of Altman warns that extracting its models' reasoning at scale could help rivals train capable models without preserving the same guardrails. Model distillation is a machine learning technique that can involve using one model's outputs to train another - in adversarial cases, by sending bulk queries designed to reproduce the larger model's reasoning and capabilities. Both the feds and major US AI companies, including Google and Anthropic, have accused Chinese rivals - and specifically Moonshot AI - of using distillation to reproduce capabilities from American models. In a Wednesday blog, OpenAI chimed in, saying it spotted and ultimately disrupted an adversarial distillation campaign that ran nearly all of July. The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations," according to the blog. Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service." The queries began on July 1, and while they started slowly, we observed high-volume spikes on July 24 and 25 consisting of 16,000 requests using a relevant extraction pattern from over 4,000 users," OpenAI said. Upon investigating the incident, the AI giant identified related prompt-pattern activity" across more than 15,000 users. OpenAI fully disrupted the campaign on July 28, we're told. While OpenAI said that it's unclear whether all of the operators during the July time period were linked to just one rival AI company, the core cluster" of the theft came from Moonshot AI, which developed Kimi. The Register reached out to Moonshot AI for comment and did not receive an immediate response. We also asked OpenAI which of its models were targeted during the July campaign, but did not hear back. It's worth noting that, in late July, US President Donald Trump's Assistant for Science and Technology Michael Kratsios also accused Moonshot AI of creating its Kimi K3 model by distilling Anthropic's Fable. Anthropic's Claude Opus 5.5 model, released a week ago, comes with a defense against distillation called "preserved thinking" that it introduced with Fable 5.1. Adversarial distillation poses safety and national security risks," OpenAI said on Wednesday, echoing earlier gripes from American companies and government officials. Extracted reasoning could be used to train another model without preserving the safeguards applied to the original model's user-facing outputs," OpenAI added. At scale, distillation can also accelerate the transfer of advanced capabilities without requiring the same investment in safety. These concerns become heightened as models gain capabilities in dual use domains." In response, OpenAI said it banned the model-copying accounts tightened signup and infrastructure controls and expanded monitoring efforts. It also closed a pathway that allowed someone who already possessed another user's encrypted reasoning to replay it and recover its contents," and worked with service providers to ensure that this type of distillation activity didn't just move to third-party services. Additionally, OpenAI shared the details of its investigation with other AI firms, through the Frontier Model Forum, and government information-sharing programs.(R)