OpenAI accuses Moonshot AI of mass GPT reasoning extraction attempts
- Doom: OpenAI says Moonshot AI launched over 10,000 attacks targeting GPT hidden reasoning data
- Boom: OpenAI disrupted the coordinated extraction campaign and linked it to Kimi
- Neutral: Moonshot AI is a Chinese company; the accusation adds to US-China AI rivalry
- Neutral: Futurism reported on the notification email OpenAI sends affected organizations
The story in full
OpenAI publicly accused Moonshot AI, the Chinese company behind the Kimi model, of orchestrating a coordinated campaign to extract hidden reasoning data from its models, with the effort involving over 10,000 attacks. The disruption was reported on September 30, 2026, with coverage from Bloomberg, CNBC, and multiple other outlets confirming OpenAI took action against the campaign.
Moonshot AI's Kimi product is at the center of OpenAI's allegations, which center on attempts to reverse-engineer or extract proprietary model reasoning. The dispute places OpenAI and a Chinese AI competitor in direct conflict over model security and intellectual property, though Moonshot AI's response to the accusations has not been established by the available sources.
Analysis
376 wordsOn September 30, 2026, OpenAI publicly accused Moonshot AI, the Chinese company behind the Kimi conversational AI product, of running a coordinated campaign to extract hidden reasoning data from GPT models. OpenAI said the effort involved more than 10,000 distinct attacks and that it successfully disrupted the operation. The accusation was confirmed across multiple outlets including Bloomberg and CNBC, and Futurism reported on the notification emails OpenAI sends to organizations whose infrastructure was implicated in or affected by such campaigns. Moonshot AI had not issued a public response as of the available reporting.
The stakes here extend well beyond a single security incident. Hidden reasoning data, sometimes called chain-of-thought traces, represents some of the most proprietary material a frontier model developer holds. If a competitor could extract it at scale, they would gain detailed insight into how a model structures its thinking, potentially shortcutting years of expensive training and research. The accusation also lands in a charged geopolitical context, adding a concrete technical flashpoint to the broader US-China competition in AI development. What remains genuinely in dispute is the attribution itself: OpenAI has made the link to Kimi, but without a response from Moonshot AI, the question of intent, authorization, and the precise mechanism of the attacks is unresolved in public.
None of the three camps had published reactions as of the available sources. Pro-AI voices would typically treat this as evidence that frontier model security infrastructure is working as intended, pointing to OpenAI's disruption of the campaign as a sign that the industry can defend itself against extraction attempts. Anti-AI voices would likely use the story to argue that the concentration of powerful proprietary systems in a small number of companies creates exactly the kind of high-value target that invites adversarial behavior, raising questions about systemic risk. Middle-ground observers would probably focus on the difficulty of attribution in these cases and call for clearer international norms around model security and intellectual property.
The next meaningful development to watch is whether Moonshot AI issues a formal response to the accusations, and whether OpenAI or any regulatory body moves toward legal or diplomatic action. Any technical disclosure about how the extraction attempts were structured and detected would also significantly sharpen the public understanding of what actually occurred.
What Anti-AI voices are sayingOpenAI ignored repeated internal warnings about model security and inadequate monitoring, leaving its systems vulnerable. Critics also argue that selling public API access hands rivals the very data they need, and that self-regulation is insufficient.
Quote 1 of 7What Middle Ground voices are sayingThe incident suggests quiet behind-the-scenes maneuvering to extract proprietary AI reasoning capabilities, framed as an unsurprising feature of a fast-moving and competitive industry.
Top quoteAdd your take
0 reader votesSign in with Google to pick a side and post. Your vote moves the story's Doom / Boom score.
No more Pro-AI reactions
More Anti-AI reactions (6)
“corporate greed is what is fuelling this reckless race to be the top dog in the industry.”
bcshelby.bsky.social, Bluesky · 16:19 UTC“Trump just said he wouldn't move to regulate AI. "They'll regulate themselves!"”
CGray, Bluesky · 19:48 UTC“Months before #OpenAI’s artificial intelligence went rogue, 2 employees raised an alarm with top executives. They were ignored. In emails, the employees said they worried that OpenAI’s newest #AI models were not being appropriately monitored ... By Sheera FrenkelDustin Volz”
Desert Flower, Bluesky · 16:58 UTC“Selling public API access to advanced models isn't a moat—it just bankrolls the dataset your rivals are gunning for.”
Zubiqo, Bluesky · 17:49 UTC“Employees and security researchers said that they had cautioned the company on safely testing its #AI models and strengthening its corporate infrastructure, but that #OpenAI did not listen.”
Empowering Main St. Before Wall St., Bluesky · 14:36 UTC“And Trump wants AI companies to police themselves!”
Paul Hallasy, Bluesky · 14:17 UTC
No more Middle Ground reactions
Sources
6 articles from 6 outlets- CNBCOpenAI links China’s Moonshot AI to attempt to extract its models’ reasoning
- FuturismHere’s the Email You Get When an OpenAI Model Hacks Your Organization
- finance.biggo.comOpenAI Accuses Moonshot AI of Launching Over 10,000 Attacks in Attempt to Crack GPT's Hidden Reasoning
- Unite.AIOpenAI Disrupts Coordinated Model-Reasoning Extraction Campaign
- Crypto BriefingOpenAI disrupts extraction attempts linked to Moonshot AI’s Kimi
- bloomberg.comOpenAI Blames Moonshot for Mass Data Extraction on Its AI Models

