OpenAI disrupts model distillation campaign linked to Moonshot AI

FoxTPNL / Wikimedia Commons (CC BY 4.0)

OpenAI disrupts model distillation campaign linked to Moonshot AI

The company said operators used thousands of accounts to extract protected reasoning from its models in an effort consistent with training or improving rival systems.

OpenAI says it caught a large-scale effort by users linked to Moonshot AI trying to extract protected reasoning from its models. The company says it disrupted the operation.

The timing is awkward for Moonshot. The Chinese lab’s flagship Kimi K3 model has been drawing attention for its coding and reasoning chops. Now the question is how much of that skill was built at home.

What OpenAI found

OpenAI identified the extraction attempt as large-scale and tied it to users affiliated with Moonshot AI. The target was reasoning that OpenAI treats as protected. That is the step-by-step problem solving that makes modern AI models useful for hard tasks.

The episode fits a broader pattern of US allegations about industrial-scale “distillation.”

Think of distillation like a student copying a star pupil’s homework. The star pupil spent years learning the material. The copier just harvests the answers and studies them until they can produce similar work.

In AI terms, distillation means feeding a powerful model many prompts. You collect its outputs and use them to train a competing system. The copy can pick up capabilities without the original’s research and compute bill.

OpenAI is not the only American lab pointing fingers at Moonshot. Anthropic has accused the company of sending nearly 300,000 requests through fraudulent accounts for distillation purposes.

Advertisement

The allegations against Moonshot include the use of fake user accounts and a range of evasion tactics. The goal, per the accusers, was to reach models from both OpenAI and Anthropic.

Washington has weighed in too. Michael Kratsios, director of the White House Office of Science and Technology Policy (OSTP), has accused Moonshot of stealing from Anthropic’s Fable model.

Moonshot denies the allegations. The company maintains that its results come from legitimate innovation, not from siphoning American models.

Why Kimi K3 is at the center of this

Moonshot released Kimi K3 on July 16, 2026. The model has 2.8 trillion parameters.

K3 is also open-weight. That means Moonshot published the trained model’s weights, so outside developers can download it and run it themselves. American rivals from OpenAI and Anthropic keep their top models behind paid access.

That combination makes K3 a real competitor. It is a giant model that anyone can run, and it has posted strong results in coding and reasoning. It goes head-to-head with established US systems.

A familiar fight in the US-China AI race

None of this is entirely new. US government warnings about Chinese labs pulling billions of tokens from American AI models go back to at least late 2024.

Moonshot also is not the first Chinese lab to face this kind of accusation. Similar claims have been leveled at DeepSeek.

The pattern tends to repeat. A Chinese lab ships a model that performs surprisingly well. American labs and officials raise distillation concerns. The Chinese company insists it simply did the work.

What has changed is the volume of the accusations. OpenAI, Anthropic and a senior White House science official have now all aimed at the same company.

What this means

For AI developers, the first-order consequence is tighter security around model access. Fraudulent accounts and evasion tactics are the tools named in the allegations. Labs will likely keep investing in detecting and shutting down that kind of behavior, as OpenAI says it did here.

The policy angle may carry the most weight. Kratsios’s comments show that distillation has moved from a corporate complaint to a matter the US government is discussing openly. That raises the possibility of more regulatory scrutiny of Chinese AI firms, and potentially sanctions, though nothing in the current allegations confirms specific action.

For now, the key thing to track is whether the accusations turn into evidence, and then into policy. OpenAI says it disrupted this operation. Anthropic has a request count. A senior official has named a specific model.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.
OpenAI disrupts model distillation campaign linked to Moonshot AI
OpenAI disrupts model distillation campaign linked to Moonshot AI

The company said operators used thousands of accounts to extract protected reasoning from its models in an effort consistent with training or improving rival systems.

FoxTPNL / Wikimedia Commons (CC BY 4.0)

OpenAI says it caught a large-scale effort by users linked to Moonshot AI trying to extract protected reasoning from its models. The company says it disrupted the operation.

The timing is awkward for Moonshot. The Chinese lab’s flagship Kimi K3 model has been drawing attention for its coding and reasoning chops. Now the question is how much of that skill was built at home.

What OpenAI found

OpenAI identified the extraction attempt as large-scale and tied it to users affiliated with Moonshot AI. The target was reasoning that OpenAI treats as protected. That is the step-by-step problem solving that makes modern AI models useful for hard tasks.

The episode fits a broader pattern of US allegations about industrial-scale “distillation.”

Think of distillation like a student copying a star pupil’s homework. The star pupil spent years learning the material. The copier just harvests the answers and studies them until they can produce similar work.

In AI terms, distillation means feeding a powerful model many prompts. You collect its outputs and use them to train a competing system. The copy can pick up capabilities without the original’s research and compute bill.

OpenAI is not the only American lab pointing fingers at Moonshot. Anthropic has accused the company of sending nearly 300,000 requests through fraudulent accounts for distillation purposes.

Advertisement

The allegations against Moonshot include the use of fake user accounts and a range of evasion tactics. The goal, per the accusers, was to reach models from both OpenAI and Anthropic.

Washington has weighed in too. Michael Kratsios, director of the White House Office of Science and Technology Policy (OSTP), has accused Moonshot of stealing from Anthropic’s Fable model.

Moonshot denies the allegations. The company maintains that its results come from legitimate innovation, not from siphoning American models.

Why Kimi K3 is at the center of this

Moonshot released Kimi K3 on July 16, 2026. The model has 2.8 trillion parameters.

K3 is also open-weight. That means Moonshot published the trained model’s weights, so outside developers can download it and run it themselves. American rivals from OpenAI and Anthropic keep their top models behind paid access.

That combination makes K3 a real competitor. It is a giant model that anyone can run, and it has posted strong results in coding and reasoning. It goes head-to-head with established US systems.

A familiar fight in the US-China AI race

None of this is entirely new. US government warnings about Chinese labs pulling billions of tokens from American AI models go back to at least late 2024.

Moonshot also is not the first Chinese lab to face this kind of accusation. Similar claims have been leveled at DeepSeek.

The pattern tends to repeat. A Chinese lab ships a model that performs surprisingly well. American labs and officials raise distillation concerns. The Chinese company insists it simply did the work.

What has changed is the volume of the accusations. OpenAI, Anthropic and a senior White House science official have now all aimed at the same company.

What this means

For AI developers, the first-order consequence is tighter security around model access. Fraudulent accounts and evasion tactics are the tools named in the allegations. Labs will likely keep investing in detecting and shutting down that kind of behavior, as OpenAI says it did here.

The policy angle may carry the most weight. Kratsios’s comments show that distillation has moved from a corporate complaint to a matter the US government is discussing openly. That raises the possibility of more regulatory scrutiny of Chinese AI firms, and potentially sanctions, though nothing in the current allegations confirms specific action.

For now, the key thing to track is whether the accusations turn into evidence, and then into policy. OpenAI says it disrupted this operation. Anthropic has a request count. A senior official has named a specific model.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.