Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

OpenAI claims Moonshot AI ran a distillation campaign, as open-weight rivals close the gap

OpenAI said on 1 October that it disrupted a coordinated campaign to extract reasoning from its models, attributing a core cluster of the activity to individuals associated with China's Moonshot AI, the developer of Kimi. The company said the activity surged to 16,000 requests from more than 4,000 users over two days in late July.

AI & modelsAnalysisRachel NwosuPublished: 1 October 20266 min readSources 7
OpenAI claims Moonshot AI ran a distillation campaign, as open-weight rivals close the gap

CNBC reported the disclosure on Thursday, and The Register picked it up the same day. Both outlets flagged the timing: it landed the same week Anthropic went public with its own allegations against Chinese developers. OpenAI says the activity began in early July and peaked on 24 and 25 July. By 28 July, the company says, it had shut the campaign down completely.

Nothing was breached.

OpenAI told CNBC that the operators did not break its encryption, compromise its databases or reach stored user conversations. Instead, the company says, they manipulated model interactions so that protected reasoning came back in a form the requester could read. The Register quotes OpenAI's own wording from a Wednesday blog: "The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations."

What distillation actually means here

OpenAI calls the technique "adversarial distillation." The idea is not new in machine learning: one model's outputs get used to train or improve another. What OpenAI describes is the scaled-up version, where bulk queries are built to reproduce a larger model's reasoning and capabilities, not just its final answers. The company argues that extracting reasoning lets a rival reproduce advanced behaviour without spending the same money on training and safety work. It frames the issue as a safety and national security matter, not just a commercial one.

The Register was blunt about the optics. Its headline on 30 September called OpenAI's complaint ironic. OpenAI "hoovered up vast amounts of internet content amid copyright fights," the paper wrote, while treating distillation of its own models as a security risk. That framing is the strongest counter-argument in the current coverage, and it is worth stating plainly: the same argument about training data cuts differently depending on who is making it.

OpenAI says it is unclear whether every operator involved belonged to a single actor. It attributes only a "core cluster" to people associated with Moonshot AI. Moonshot did not immediately respond to requests for comment from either CNBC or The Register. The Register also asked OpenAI which of its models were targeted and did not hear back. That detail matters, because the severity of any distillation claim depends on what was copied.

"Adversarial distillation poses safety and national security risks," OpenAI said on Wednesday. "Extracted reasoning could be used to train another model without preserving the safeguards applied to the original model's user-facing outputs."

The wider fight over open weights

The accusation sits inside a broader shift in how AI capacity is distributed. Open-weight models have moved from a niche publishing habit to a serious share of production traffic. Recent industry coverage cited in the dossier's context feed claims open-weight models processed a majority of AI tokens for the first time, and that token bills are pushing enterprise workloads toward open-weight options. None of that comes from the sources below, so treat it as direction of travel rather than a verified number.

What is verifiable is that the pressure is real. Anthropic's Claude Opus 5.5, released a week before OpenAI's blog, ships with a defence against distillation called "preserved thinking," introduced alongside Fable 5.1, according to The Register. That is a product-level response to a training-level problem. If model makers are now baking anti-extraction features into shipped models, they are treating distillation as permanent, not as a one-off incident.

There is also a paper trail on the government side. The Register notes that in late July, Michael Kratsios, assistant to President Donald Trump for science and technology, accused Moonshot AI of building its Kimi K3 model by distilling Anthropic's Fable. That claim predates OpenAI's blog by roughly two months, and it covers a different company's model. The accusations are not isolated to one lab or one incident.

Meanwhile, the open-weight stack keeps shipping

While US labs argue about copying, the open-weight ecosystem published a steady stream of work this week. Meta's research arm released Context Language Models, a method that treats a model's context as a file the model updates itself. The repository comes from a team spanning the University of Washington, Meta Superintelligence Labs, MIT and Trillium Labs. It reports 11.4 percent higher accuracy with 21.5 percent fewer FLOPs on BrowseComp-Plus, and a 47.6 percent improvement for Qwen3.5-9B on the same benchmark after online reinforcement learning, using 12 percent fewer FLOPs.

Separately, the UK AI Security Institute and Meridian Labs published Inspect, an open-source evaluation framework for frontier models. Inspect ships with more than 200 pre-built evaluations and supports running arbitrary external agents such as Claude Code, Codex CLI and Gemini CLI inside a sandbox. It is the kind of infrastructure that makes independent testing of open-weight models cheaper. That is awkward for anyone arguing that capability transfer should be restricted.

There is also a volunteer angle. A project called Coop is pretraining a small model on donated consumer hardware and free service tiers, with pseudo-gradients submitted as Hugging Face pull requests and aggregated by a stateless GitHub Actions cron job. Its stage one run, a 15 million parameter model on TinyStories, finished past its Chinchilla-optimal budget in six days, with validation loss falling from 9.01 to 2.8. It is small. It is also proof that the training loop can run without a data centre.

And a non-transformer model called PSSA, written from scratch in Rust, claims linear-time inference with a recurrent state-space layer and an episodic memory bank. The project's own repository says it generates text about twelve times faster than a matched transformer on the same CPU and learns faster at matched parameters. Its training pipeline still depends on DeepSpeed, a limitation the authors acknowledge. Treat the benchmark claims as claims from the project, not independently verified results.

Why the accusation is hard to adjudicate

The uncomfortable part is that both sides can point at real behaviour. OpenAI can point at 16,000 requests in two days from more than 4,000 users, a pattern it says violated its terms of service. Critics can point at the training-data lineage of every frontier model built in the US. Neither fact cancels the other, and the dossier does not contain enough detail to settle which model was targeted or how much capability actually transferred.

OpenAI says it banned the accounts, tightened signup and infrastructure controls, expanded monitoring, and closed a pathway that let someone replay another user's encrypted reasoning to recover its contents. It shared findings through the Frontier Model Forum and government information-sharing channels. Those are concrete mitigations, and they describe a defence against extraction rather than a fix for the underlying economics: as long as distillation is cheaper than training, someone will attempt it.

Comments 0

Sources

7
  1. 01AI race heats up as OpenAI flags alleged model-copying campaignEN
  2. 02Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody elseEN
  3. 03Context Language Models (CLMs)EN
  4. 04Inspect: An open-source framework for large language model evaluationsEN
  5. 05Coop: A small language model pretrained by volunteersEN
  6. 06PSSA: A non-transformer language model written from scratch in RustEN
  7. 07OpenAI unveils AI assistant 'dots' while safety worries delay new modelEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Rachel Nwosu

Rachel Nwosu

AI, models and technology

Rachel Nwosu covers AI, models and technology for FLASH24, working from public model documentation, benchmark releases and repository histories rather than press summaries, and she skips announcements that arrive without reproducible numbers. She checks training-data claims against dataset cards and reruns reported metrics where code is available. She spends much of her week interviewing researchers and engineers, tracking model launch calendars, and comparing vendor benchmarks with independent evaluations. Outside the desk she runs 3D printers, restores old computers, and tests how models learn from internet junk. She does not publish benchmark figures she cannot trace to a source.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.