WORLD

OpenAI joins Anthropic in accusing Moonshot AI of 'distillation'

by
Jung Mok-hee
Published : Oct. 1, 2026 - 14:16:52
    • Copy Completed!

View Korean Original

Data requests peaked at 16,000 in late July; attacks evolved as defenses changed

The logo of Moonshot AI [Reuters]
The logo of Moonshot AI [Reuters]

OpenAI has publicly accused users linked to Chinese AI company Moonshot AI of attempting to extract the reasoning capabilities of its most advanced models through large-scale data scraping. The accusations add to a growing dispute over so-called "adversarial distillation" — a technique for replicating the performance of cutting-edge AI models at a fraction of the cost — as the technology competition between the United States and China intensifies.

In a blog post Wednesday (local time), OpenAI said it had detected and blocked a large-scale operation by users connected to Moonshot AI who attempted to extract hidden reasoning information from its GPT models. The extracted data could be used to train other AI models to replicate GPT's problem-solving methods and performance, OpenAI said.

According to Bloomberg and other outlets, the activity began in early July, with requests using specific reasoning-extraction patterns jumping to 16,000 on July 24 and 25. More than 4,000 users were found to have been involved.

OpenAI said it could not identify all those who attempted access as a single entity, but that users connected to Moonshot played a significant role.

OpenAI's accusation against Moonshot comes amid a wave of criticism from Silicon Valley and the Donald Trump administration alleging that Chinese AI developers have been systematically using distillation techniques to extract proprietary knowledge from American companies and build competing chatbots at far lower cost.

This marks the first time OpenAI has publicly named Moonshot, following a threat report Anthropic published in September.

OpenAI has been coordinating with Anthropic and Google, a unit of Alphabet, on ways to counter adversarial distillation by Chinese companies and others.

Caroline Ghirra, OpenAI's head of national security strategy initiatives, said the company's concern was not with open models or legitimate distillation but with violations of its terms of service. "It's a shared challenge for the US to continue to lead across every domain," she said.

OpenAI said it had been progressively concealing its models' reasoning processes — providing only final answers without explanations — to limit distillation. Users linked to Moonshot circumvented this by asking models in one conversation to copy encrypted reasoning content and paste it into a model in a separate conversation, OpenAI said.

OpenAI described the technique as a narrow jailbreak that exposed reasoning content in a form readable by its internal servers, adding that the encryption had not been fully decoded.

An AI industry official who asked not to be named said the fact that attack methods evolved each time OpenAI changed its defenses was evidence that the distillation was providing useful training material to the Chinese side.

Anthropic had earlier alleged that Moonshot secretly routed thousands of user requests through its Claude models and then used the responses — presenting them as its own — to train its Kimi model.

The 16,000 requests OpenAI disclosed represent only a fraction of the millions Anthropic reported in its largest documented case. A source familiar with OpenAI's operations said the figures are difficult to compare directly because the counting periods and detection methods differ.

The Chinese government has denied all distillation allegations raised by the US side and has warned it will retaliate if Washington moves to impose sanctions.


mokiya@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ