16,000 Requests, 4,000 Users: OpenAI Says It Caught an Attempt to Steal How Its AI Thinks
Kaino
4d agoOct 1, 2026, 12:00 AM23 views

16,000 Requests, 4,000 Users: OpenAI Says It Caught an Attempt to Steal How Its AI Thinks

OpenAI says it disrupted a July campaign to extract protected reasoning traces, linking part of it to individuals associated with Moonshot AI. No technical evidence has been published.

OpenAIMoonshot AImodel distillationreasoning extractionAI securityOpenAI disruptionChina AI competition

OpenAI says it blocked a coordinated July campaign that attempted to extract protected reasoning from its models at scale — and says part of the activity was linked to individuals associated with Chinese AI company Moonshot AI. OpenAI reports disrupting the accounts and related activity by July 28.

This isn't a claim about ordinary chatbot use. OpenAI says the operation specifically targeted reasoning material it treats as protected, using attempts spread across separate conversations to decrypt and reconstruct those outputs. At its peak, the company says the activity generated roughly 16,000 requests matching its extraction patterns from more than 4,000 users, and it took action against a broader set of over 15,000 accounts.

Those numbers need context before they get repeated as something bigger than they are. OpenAI's own account separates the activity it links to Moonshot-associated individuals from the larger pool of related accounts it acted against — 15,000 restricted accounts does not mean 15,000 people working for Moonshot, or even participating in one coordinated effort.

Here's the real gap: OpenAI makes a specific attribution — that a core part of the activity was associated with individuals linked to Moonshot AI — but it does not establish that Moonshot AI itself directed, approved, or knew about any of it. CyberScoop reports that OpenAI described the method as a novel technique to bypass protections around reasoning outputs, but notably did not release the technical evidence behind the attribution. That means outside researchers can't currently verify the bypass method, assess how it worked, or rule out alternative explanations for the account activity.

What makes this worth watching regardless of the attribution dispute: OpenAI is now treating reasoning traces as a distinct, higher-sensitivity category than normal model outputs — worth active monitoring and account-level enforcement, separate from how it handles typical high-volume use or prompt experimentation. That's a meaningful shift in how providers think about what needs defending, especially as distillation concerns escalate across the industry.

Bottom line: OpenAI has made a real, specific security disclosure — it genuinely did disrupt large-scale activity it considered an extraction attempt. What it hasn't done is publish the evidence needed to independently verify Moonshot AI's organizational involvement, or to confirm the operation actually succeeded in extracting anything useful. This is one more data point in a bigger industry pattern around AI distillation — not yet a settled case against a named company.

Key takeaways
  • 1

    OpenAI reports disrupting the accounts and related activity by July 28.

  • 2

    OpenAI says the operation specifically targeted reasoning material it treats as protected, using attempts spread across separate conversations to decrypt and reconstruct those outputs.

  • 3

    At its peak, the company says the activity generated roughly 16,000 requests matching its extraction patterns from more than 4,000 users, and it took action against a broader set of over 15,000 accounts.

Continue reading

Latest from Kaino News