Security News

OpenAI Says Chinese Rival Used Mass Queries to Copy Its AI Model's Reasoning

The Register · 1 Oct 2026
Key Takeaway Businesses relying on third-party AI tools should ask vendors how they monitor for abuse of their APIs, since large-scale data extraction attempts can affect service reliability and model integrity.

OpenAI says it detected and shut down an adversarial 'distillation attack' that ran through most of July, in which attackers sent large volumes of carefully crafted queries designed to extract its model's internal reasoning rather than hack its systems directly. According to OpenAI, no encryption was broken and no databases or user conversations were accessed; instead, operators manipulated interactions at scale to reproduce protected outputs, breaching its terms of service.

The activity reportedly started slowly on 1 July before spiking on 24 and 25 July, when OpenAI observed 16,000 suspicious requests from more than 4,000 users. A wider investigation uncovered similar patterns across over 15,000 accounts before the campaign was fully disrupted on 28 July. OpenAI says the 'core cluster' behind the activity traces back to Moonshot AI, the Chinese developer behind the Kimi model, though it is not certain every user involved was linked to a single company.

This follows similar accusations from Google, Anthropic and US officials, who have separately alleged that Chinese AI firms, including Moonshot AI, have used distillation techniques to replicate the capabilities of American models without the same safety guardrails. OpenAI and Moonshot AI have not confirmed further details publicly.

AI security OpenAI data extraction China model distillation
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.