AI Research Atlas

Disrupting a coordinated model-distillation campaign

OpenAI · 30 September 2026

OpenAI says it disrupted a campaign extracting protected reasoning from its models and attributes a core cluster to people associated with Moonshot AI.

Activity from 2026-07-01 spiked on 2026-07-24 and 07-25 with 16,000 requests from over 4,000 users; related patterns reached over 15,000 users, disrupted by 07-28. Attackers replayed encrypted reasoning across conversations. OpenAI hardened hidden-reasoning protections.

Date
Wednesday, 30 September 2026
Lab
OpenAI
Kind
paper
Access
research preview

Figures

MeasureValueMeasured by
Users in the related prompt-pattern clustermore than 15,000
disrupted by 2026-07-28
company

Attribution to Moonshot AI is OpenAI's own assessment ("a core cluster"); the post says it is unclear whether all operators were one actor, and Moonshot's response was not found. Distillation as a diffusion route for reasoning capability is the core issue for B20.

Sources

  1. openai.com/index/disrupting-a-coordinated-model-distillation-campai/
  2. thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html
  3. decrypt.co/379890/openai-china-moonshot-copy-ai-hidden-reasoning

This record was checked against its sources on 6 October 2026. How we check

Read the daily brief for 30 September 2026