OpenAI Blames Moonshot for Mass Data Extraction on Its AI Models
OpenAI accused its Chinese rival Moonshot AI of being responsible for a wide-scale effort to extract data from its GPT artificial intelligence systems that could be used to reproduce the reasoning and capabilities of the company’s most advanced models.
In a blog post Wednesday, OpenAI disclosed that it observed thousands of attempts by users associated with Moonshot to decipher hidden information about how its models reason through problems. Coordinated efforts to glean the data began in early July, peaking at 16,000 requests later in the month. Though it couldn’t attribute all the operators to a single actor, OpenAI said that users associated with Moonshot played a significant role.
OpenAI’s accusations against Moonshot add to a growing pile of claims from Silicon Valley and the Trump administration that Chinese AI developers are systematically extracting proprietary knowledge from American firms using a technique known as distillation to build a rival generation of chatbots at a fraction of the cost. Moonshot, whose breakthrough Kimi K3 model upended assumptions about Chinese AI capabilities, has faced particular scrutiny in Washington for its rapid gains on US rivals.
Read More: US Says Alibaba, DeepSeek ‘Systematically’ Tapped AI Models
While distillation is a common AI industry technique, where outputs from a state-of-the-art model are used to train a less-sophisticated one, the practice can violate developers’ terms of service when employed at an industrial scale. OpenAI, Anthropic PBC and Alphabet Inc.’s Google have been coordinating on ways to counter what they call adversarial forms by distillation — including by firms from China.
“Our concern is about violation of our terms of service, not open models or legitimate distillation,” said Caroline Zier, lead for strategic national security policy initiatives at OpenAI. “This is also a shared challenge of ensuring the US remains in the lead on all fronts, which is why we share findings with other developers and relevant government partners, and will also continue to invest in stronger protections. We support a thriving open-weight model ecosystem and the US leading it.”
Representatives for Moonshot didn’t immediately respond to requests for comment. China’s government has rejected previous distillation accusations from Silicon Valley firms and the Trump administration, warning that it would retaliate against any penalties imposed by the US government.
Read More: Why Distillation Is a Big Worry for US AI Companies: Explainer
In part to limit damage from distillation attempts, OpenAI has been increasingly hiding its models’ reasoning chains, providing users with answers, rather than explanations of how it reached those answers. Individuals tied to Moonshot got around those restrictions, OpenAI’s blog says, by copying encrypted reasoning from one conversation and asking a model in another conversation to transcribe it.
The method involved a narrow jailbreak to reveal a version of the reasoning legible to the company’s internal servers and did not decrypt it, OpenAI said. The evolving nature of the attacks as OpenAI changed its defenses is evidence that such distillation provides valuable training, according to a person at an AI lab, who asked not to be named for confidentiality reasons.
OpenAI’s accusations highlight the intensifying competition for OpenAI and other American companies, which are grappling with a growing challenge from Chinese rivals including DeepSeek and Minimax that offer more affordable open-weight models. While some AI developers in the US, including OpenAI, offer open systems, much of their focus has been on closed or proprietary systems that they sell to customers.
A few weeks after Kimi K3 launched, White House science and tech policy advisor Michael Kratsios said in a social media post that Moonshot had accessed Nvidia Blackwell computing servers, which are banned for sale to Chinese companies, and used a “sophisticated internal platform” to extract data from US models.
Moonshot has a computing power agreement with Alibaba Group Holding Ltd. for the use of around 20,000 Nvidia Corp. chips, a cluster that makes up a substantial chunk of the overall computing capacity it uses for Kimi models, Bloomberg News has reported.
The disclosures mark the first time OpenAI has accused Moonshot, but it follows a threats report from Anthropic last month that said Moonshot covertly routed thousands of user requests to the US firm’s Claude models and passed off the responses as its own, while using the answers to help train Kimi models.
OpenAI’s latest disclosure of a distillation attempt involving 16,000 requests is only a fraction of the size of the largest incidents reported by Anthropic, which recorded distillation in the millions of exchanges.
A person familiar with OpenAI’s thinking, who also spoke on condition of anonymity for confidentiality reasons, cautioned that the figures may cover different time periods and use different detection methods, so they may not be directly comparable. If an attack is disrupted early, there will also be less volume overall, the person added.
Read More: China’s Open-Weight Models to Be Spared US Tests, US Firms Told
Distillation accusations by US companies have their critics, including David Sacks, a venture capitalist and President Donald Trump’s former AI czar. Sacks has characterized the reports as an attempt to get the US to ban open models that challenge OpenAI and Anthropic’s business model. China has also fervently opposed claims that its companies are engaging in unfair development practices.
OpenAI has also sought clarity on antitrust law to allow developers to share safety and security related information and wants open-weight developers to participate, the people added. Senator Jim Banks, an Indiana Republican and Senator Adam Schiff, a California Democrat, have proposed legislation that would create a narrow antitrust exemption for sharing information related to unauthorized distillation and other AI safety threats.
To some extent, OpenAI has already been sharing information with others that might face similar distillation attempts, and it said in the blog that it had told industry partners about this incident through the Frontier Model Forum. It also communicated it to government channels, a pathway blessed by a national security policy memo signed by Kratsios in April.