On 30 September OpenAI said it had disrupted a coordinated adversarial distillation campaign that began on 1 July. The company attributes the core of the activity to individuals associated with Moonshot AI, the developer of Kimi. No encryption was broken and there was no direct access to stored user conversations.
- The peaks were on 24 and 25 July: 16,000 requests from more than 4,000 users. A related cluster of over 15,000 users was cut off by 28 July.
- OpenAI notes the figures are attempts, not necessarily successful extractions.
- A path that let someone replay and recover another user's encrypted reasoning has been closed.
You copy a model's encrypted reasoning from one conversation. You open another and ask the model to decrypt and transcribe it for you.
That is one of the methods OpenAI describes. It is not a break-in in the classic sense, nobody got into a database. The model was asked to read aloud something that was meant to stay hidden, and OpenAI has closed a path of this kind.
Why steal the reasoning and not the answers? Because the answer says what, and the reasoning says how. If you are training your own model, the how is worth more. OpenAI adds the more dangerous side: this way capability is transferred without the safeguards applied to the visible answer.
Two things we do not know. How many of the attempts succeeded, because OpenAI itself says the figures are attempts. And what Moonshot says, because there is no word from them in the text.
If you build a service that moves a model's reasoning between sessions or accounts, OpenAI explicitly warns that systems with portable or replayable reasoning may face similar risks. That sentence is for engineers, not for headlines.