On September 30, OpenAI announced with unusual candor in its blog: over the course of July, the company detected and stopped a coordinated campaign aimed at stealing the protected "thinking" records of its models. The main cluster of activity is assessed as linked to individuals affiliated with the Chinese company Moonshot AI — the maker of the Kimi chatbot. OpenAI called it "adversarial distillation" and assessed it as a threat to security and national security.
This is one of the most sensational episodes of the "distillation wars" intensifying in recent months: the AI race is now not only about who builds the stronger model, but also about who can protect their model's "brain" from theft.
Campaign timeline: what happened in July
Per OpenAI, the earliest observed activity dates to the first week of July. Initially volume was low, but on July 24–25 a sharp spike was observed: 16,000 requests matching the extraction pattern from over 4,000 users were recorded. Follow-up investigation found related "query-pattern" activity covering over 15,000 users. By July 28 the campaign was fully stopped.
Importantly, OpenAI stresses that operators didn't break its encryption system, enter the database, or gain direct access to stored user conversations. Instead, they manipulated interaction with the model so that the protected thinking was recreated in a form visible to the requester — in a coordinated, large-scale manner violating the company's terms of use.
What is "protected thinking" and why is it so valuable?
Modern reasoning models work through a task in an internal "draft" before answering — this is called chain-of-thought. OpenAI encrypts this internal record and doesn't show it to the user: it reveals how the model solves the task, sometimes including data deliberately hidden from the final answer.
OpenAI's explanation:
"Protected thinking is the model's internal record of working through the task; extracting it can reveal data hidden from the final answer and help others recreate the model's capabilities."
This is exactly why these records are a gold mine for competitors: a lab that obtains them can "copy" frontier-model capabilities without billions in research spending. The legal form of distillation is widely used in machine learning — a small "student" model learns from the outputs of a large "teacher" model. The problem begins when it's done secretly and in violation of a rival's terms of use: then it becomes "adversarial distillation."
How did the new attack method work?
OpenAI writes that attackers tried "new methods": encrypted thinking from one conversation was copied, and in another conversation the model was asked to decrypt it and output the hidden content as text. In other words, the strong model wasn't directly breached — its encrypted "draft" was shown to another, less-protected copy, forcing it to read.
Curiously, independent researchers found this vulnerability before OpenAI. An August 2026 study by scientists at MATS Research, the ELLIS Institute in Tübingen, and Synk showed that encrypted thinking blocks are "fully compatible and interchangeable" across different sessions, users, and models within one provider's ecosystem. The researchers warned OpenAI via responsible disclosure, and the company confirmed the attack paths were indeed real. OpenAI acknowledged this work helped them understand a broader class of attacks and accelerate defenses.
OpenAI stresses that campaign operators used not only technical tools but stealth tactics: requests through thousands of fake accounts were distributed to look "natural," patterns were regularly changed to evade automated detection systems. This is exactly why the company's response included strengthening registration controls — aimed at stopping similar campaigns at an early stage in the future.
Attribution: why Moonshot AI specifically?
OpenAI writes cautiously: it can't be said precisely that all observed operators belong to one entity. However, the company concluded it "assesses the main cluster of activity as linked to individuals affiliated with Moonshot AI — the maker of Kimi." No technical evidence was provided — the company explained this by security considerations.
Moonshot AI is a Beijing-based Chinese startup known for the Kimi models. This company is not facing distillation accusations for the first time: last month rival Anthropic also accused Moonshot of secretly routing customer queries to Claude models and showing answers in Kimi's name (per The Hacker News). Per press reports, U.S. cyber agencies (NSA, CISA, FBI) in early September also accused six Chinese AI companies of industrial-scale distillation from U.S. frontier models. At publication time, Moonshot AI had not publicly commented on the accusations (per The Register).
How did OpenAI respond?
The company said it neutralized the campaign along three lines: fraudulent accounts were banned or restricted, registration and infrastructure controls were strengthened, monitoring of related networks was expanded. Technically two important vulnerabilities were closed: first, the "path" that let someone holding another user's encrypted thinking replay it and recover the content was closed; second, additional checks were added to detect and hold streaming output that could reveal thinking. For activity that went through third-party services, OpenAI cooperated with the relevant providers, identified and stopped participating accounts.
The findings were shared with industry partners via the Frontier Model Forum and with relevant government agencies via government information-sharing channels. OpenAI's main warning sounds thus:
"Adversarial distillation poses security and national security risks. Extracted thinking may be used to train another model without preserving the safeguards applied to the original model's user-visible outputs."
The company openly said it expects such attempts to grow more sophisticated in the future: as frontier models improve and some actors seek to copy capabilities more cheaply, defense must be "layered and continuously adaptive."
Why is this a national security issue?
OpenAI's main concern isn't economic but strategic: large-scale distillation accelerates the transfer of advanced capabilities — "without the same investment in security." That is, safeguards aren't copied, only the capabilities themselves are. As models grow stronger in dual-use fields — cybersecurity, biology, chemistry — this concern grows too: unprotected copied capabilities in the wrong hands can become a dangerous weapon.
Hence OpenAI frames the matter not as a purely commercial dispute but as a shared security problem for the whole industry, calling for "deeper threat-intelligence sharing."
The broader picture: distillation wars intensify
In recent months distillation has regularly made headlines. Anthropic accused Chinese labs of distilling from Claude models, U.S. agencies issued official warnings, and now OpenAI came out with a detailed technical report. In each case the pattern is the same: access via an open or semi-open API, a stream of automated requests, cheap training of a rival model on stolen capabilities.
The process has a second side: as defenses strengthen, legal researchers and small labs may find it harder to access frontier models. OpenAI itself acknowledges that "systems deployed at partners need the same protection" — i.e., models distributed via cloud providers are also open to such attacks.
Notably, OpenAI this time acted more openly than usual: a detailed technical blog post, exact dates, numbers, and an attribution assessment. This is part of the company's "security transparency" strategy: publicly announcing threats to push the whole industry toward the same defenses. But critics note such announcements also give attackers additional information about defense mechanisms — the classic security-vs-transparency balance problem.
The Uzbek context
For Uzbekistan this event may seem distant, but there are three practical takeaways.
First, most local startups and IT companies build their products on OpenAI, Anthropic, or Google APIs. As model providers' security policies tighten, API controls will strengthen, access terms and prices may change — be ready for this, prepare backup-provider and open-weight-model plans in advance.
Second, the distillation dispute questions the economics of "cheap and good-enough" models. If some labs get capabilities cheaply via distillation, the open-weight model market will get even cheaper — good news for markets like Uzbekistan (cheap AI), but it also raises the question of protecting local developments in an environment with weak IP protection.
Third, from a cybersecurity view: AI adoption in Uzbekistan's government and banking systems is accelerating. That frontier models' "thinking" records can reveal confidential data shows: government agencies and financial organizations must strengthen data-privacy requirements when using AI. Never forget that every query sent to a model can potentially be analyzed.




