# Coordinated model-distillation campaign against OpenAI: 15,000+ accounts attempt to extract protected model reasoning, linked to Moonshot AI-associated individuals

> OpenAI disrupted a coordinated adversarial model-distillation effort aimed at extracting protected internal reasoning from its models. Activity began at low volume on July 1, 2026, spiked July 24-25 (~16,000 extraction-pattern requests from 4,000+ users), and a wider cluster of 15,000+ users was fully disrupted by July 28, 2026. OpenAI attributed a core cluster to individuals associated with Moonshot AI (developer of Kimi) but said it is unclear whether all operators were a single actor.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2915
- **ID:** TL-2026-2915
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** MONITORING
- **Actor:** Individuals associated with Moonshot AI (China)
- **Detections:** 9 · **IOCs:** 4 (full data via the Threadlinqs MCP server — Purple tier)

## Description

OpenAI publicly disclosed on September 30, 2026 that it had disrupted a coordinated model-distillation campaign targeting the protected (encrypted) reasoning of its models. Per OpenAI as relayed by secondary reporting, the operators did not break the encryption or access any database or customer conversation. Instead they manipulated model interactions: encrypted reasoning produced in one conversation was copied into a second conversation, where the model was instructed to decrypt and transcribe it, using attacker-controlled prompts and reusable context. OpenAI closed a pathway that let someone who already held another user's encrypted reasoning replay it and recover its contents.

Timeline and scale: activity began around July 1, 2026 at low volume, spiked on July 24-25 with roughly 16,000 requests matching the extraction pattern from more than 4,000 users, and a broader sweep for related prompt-pattern activity identified a cluster of more than 15,000 users. The whole cluster was fully disrupted by July 28, 2026.

Attribution: OpenAI attributed a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi, while stating it is unclear whether all operators observed in the period originated from a single actor. Reporting notes OpenAI did not establish involvement of Moonshot founder Yang Zhilin or company leadership. No Moonshot response was documented in the reviewed articles.

Context: the technique class was independently described on August 10, 2026 in the arXiv paper 'Stealing Reasoning Traces from Proprietary LLM APIs', which reported that encrypted reasoning blocks from OpenAI, Anthropic and Google could be replayed into weaker sibling models to recover plaintext traces. Earlier, in February 2026, Anthropic reported industrial-scale distillation of Claude by DeepSeek, Moonshot and MiniMax via roughly 24,000 fraudulent accounts and over 16 million exchanges.

Response: OpenAI banned or restricted fraudulent accounts, tightened signup and infrastructure controls, expanded monitoring for related accounts, coordinated with third-party services the activity ran through, closed the replay pathway, added checks that detect and hold streamed output that might expose reasoning, strengthened cross-user and cross-organization protections, and shared intelligence via the Frontier Model Forum and government channels. No CVE, CVSS score, or network indicators (IPs, domains, hashes) have been published. The OpenAI primary report could not be fetched directly (HTTP 403) and facts here come from consistent secondary reporting.

## MITRE ATT&CK

- T1585.003 Establish Accounts: Cloud Accounts
- AML.T0040 AI Model Inference API Access
- AML.T0051 LLM Prompt Injection
- AML.T0005 Create Proxy AI Model
- AML.T0024 Exfiltration via AI Inference API
- AML.T0024.002 Extract AI Model

## Sources

- [OpenAI Blocks 15,000 Requests Trying to Extract Protected Model Reasoning](https://gbhackers.com/openai-blocks-15000-requests/)
- [Disrupting a coordinated model-distillation campaign (OpenAI)](https://openai.com/index/disrupting-a-coordinated-model-distillation-campaign/)
- [OpenAI says people linked to Moonshot AI ran a campaign to extract its reasoning](https://mixed-news.com/en/openai-moonshot-ai-reasoning-extraction-campaign/)
- [OpenAI says Moonshot-linked operators tried to extract hidden model reasoning](https://runtimewire.com/article/openai-moonshot-hidden-reasoning-extraction-campaign)
- [OpenAI Says Moonshot AI-Linked Users Tried to Extract its Models' Secret Reasoning](https://www.benzinga.com/markets/private-markets/26/09/62095522/openai-says-moonshot-ai-linked-users-tried-to-extract-its-models-secret-reasoning)
- [Detecting and preventing distillation attacks (Anthropic)](https://anthropic.com/news/detecting-and-preventing-distillation-attacks)
- [Encrypted Reasoning Traces Let Attackers Steal Hidden Chain-of-Thought (CSA research note)](https://labs.cloudsecurityalliance.org/research/csa-research-note-reasoning-trace-theft-llm-apis-20260812-cs/)
- [Stealing reasoning traces (Simon Willison's Weblog)](https://simonwillison.net/2026/aug/11/stealing-reasoning-traces)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2915
