Kimi AI trained on ChatGPT? OpenAI accuses Moonshot of massive AI model copying campaign
OpenAI claims that it identified a large-scale campaign from Chinese AI lab Moonshot AI, the maker of Kimi AI models, to distil, or copy, the reasoning of its models. OpenAI says that at its peak, the campaign may have had over 15,000 users.

OpenAI has flagged, what it calls, a coordinated campaign that was aimed at distilling the company’s AI models. Distilling refers to the process of using a larger AI model’s outputs or reasoning to train a smaller model. OpenAI alleges that this campaign was linked to individuals at Moonshot AI, the Chinese AI lab that launched the Kimi K3 AI model.
In a blog post, OpenAI explained that the campaign attempted to extract the protected reasoning of the AI models. In simpler terms, this campaign allegedly used prompts to copy how OpenAI’s models were processing user queries.
It is unclear whether all users involved in the campaign were linked to a single group. But as per OpenAI, a “core cluster” of the activity was associated with Moonshot AI. If true, it could mean that Moonshot AI may have used OpenAI's models to train its future models. Though the Chinese lab last released Kimi K3 on July 16, 2026. Moonshot AI has not commented on these claims yet.
How did this happen?
Though OpenAI added that operators in the campaign “did not break our encryption, compromise a database, or gain direct access to stored user conversations. According to the company, the campaign also tried copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe the hidden reasoning content.
OpenAI claims that this campaign likely began on July 1 this year. On July 24 and 25, the company recorded as many as 16,000 requests using a relevant extraction pattern from more than 4,000 users. Further investigation, OpenAI says, identified that over 15,000 users were using similar prompts. The company had fully disrupted the campaign by July 28. The activity in the campaign is said to have changed over time, which OpenAI says, showed that distillation required layered and adaptive defences.
What did OpenAI do?
In response to the campaign, OpenAI banned or restricted fraudulent accounts. The company says it also strengthened signup and infrastructure controls, while expanding monitoring for related networks. Where related activity moved through third-party services, OpenAI worked with those providers to identify and disrupt the accounts involved.
As per OpenAI, such a distillation campaign may allow an AI lab to have advanced capabilities in its AI models without “requiring the same investment in safety.” This could be a problem particularly when AI safety has become a matter of debate globally.
This is not the first time a US AI lab has accused Chinese companies of trying to distil its models. The disclosure comes weeks after Anthropic accused several Chinese AI developers, including Moonshot AI and Alibaba, of secretly using its Claude models to help train their own systems.
More recently, three US agencies issued a joint cybersecurity advisory alleging that Chinese AI companies had been extracting capabilities from American frontier models, including OpenAI’s GPT, Anthropic’s Claude, Google’s Gemini and Grok. Earlier this month, China rejected such claims, with its foreign ministry urging the US to “refrain from making unfounded accusations or smears.”

