OpenAI published on 2026-09-30 that it identified and disrupted a coordinated campaign aimed at extracting protected reasoning from its models—activity it frames as adversarial distillation: systematic, unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another (OpenAI).
This is a Desk Bot models/security briefing locked to that primary. It is not a report that Moonshot AI as an organization admitted wrongdoing, that a court found theft, or that Kimi was trained on ChatGPT. Keep actor language exact.
What OpenAI says happened
Operators did not, per OpenAI, break encryption, compromise a database, or gain direct access to stored user conversations. Instead they manipulated model interactions so protected reasoning could be reproduced in forms visible to the requester, at scale, in ways OpenAI says violated its terms of service. OpenAI defines protected reasoning as the model’s internal record for working through a task—material that can reveal information withheld from the final answer (OpenAI).
One pattern OpenAI describes at a high level: copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe hidden reasoning. Independent security researchers also disclosed related cross-model and conversation-compaction paths; OpenAI says it confirmed those paths were real. No reproduction steps here—desk stays at the company’s framing (OpenAI).
Timeline and volumes (attempted)
| Milestone | OpenAI figure |
|---|---|
| Activity began | July 1 (low volume at first) |
| Jul 24–25 spikes | 16,000 requests using a relevant extraction pattern from over 4,000 users |
| Related cluster | More than 15,000 users |
| Fully disrupted | By July 28 |
OpenAI’s footnote: these figures describe attempted, not necessarily successful, extractions (OpenAI).
Attribution (exact wording)
OpenAI: it is unclear whether all operators in the period came from a single actor. It attributes a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi—not a house claim that the Moonshot organization “ran,” “stole GPT,” or “trained Kimi on ChatGPT” (OpenAI).
This draft does not invent a Moonshot reply.
Why OpenAI says it matters
OpenAI frames adversarial distillation as posing safety and national security risks: extracted reasoning could train another model without the original’s user-facing safeguards, and at scale could accelerate capability transfer without the same safety investment—concerns it says grow as models gain dual-use capabilities. That risk framing is OpenAI’s, not a newsroom national-security conclusion, and this brief does not add PRC statute or “must share with government” claims (OpenAI).
OpenAI also says the manipulation class is not unique to its models and that it shared information via the Frontier Model Forum (and government channels) so others can harden defenses (OpenAI).
Response (high level)
Mitigations OpenAI lists: account bans/restrictions, stronger signup and infrastructure controls, expanded monitoring, stronger protections for hidden reasoning across users/workspaces/orgs/model families, closing a pathway to replay another user’s encrypted reasoning, checks on streamed output that might expose reasoning, work with third-party providers when activity moved through them, and industry/government information sharing. Investigation and mitigations continue (OpenAI).
Who should care
Frontier operators, platform security, and policy desks watching distillation as a shared industry control problem should start at OpenAI’s disruption post—read attribution as the company’s assessment, keep volumes as attempted, and leave how-to detail out of the newsroom copy.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.