On September 30, 2026, OpenAI said it had identified and disrupted a campaign that used manipulated model interactions to try to expose protected reasoning. The company reported 16,000 attempted extraction-pattern requests during spikes on July 24–25, involving more than 4,000 users, and attributed a core cluster of activity to individuals associated with Moonshot AI, the developer of Kimi.

OpenAI reports a campaign targeting protected reasoning

Protected reasoning is a model’s internal record of working through a task. OpenAI says it may reveal information that does not appear in the model’s final answer. The company described the reported campaign as an effort to make that reasoning visible through interactions with its models.

OpenAI said the activity began at low volume on July 1. On July 24 and 25, it observed spikes involving 16,000 requests that used a relevant extraction pattern. Those requests involved more than 4,000 users, and OpenAI characterized them as attempts—not a count of confirmed successful extractions.

OpenAI also reported a separate, broader cluster of related prompt-pattern activity across more than 15,000 users. The company said it had disrupted that activity by July 28.

DateEvent OpenAI reported
July 1, 2026Activity began at low volume.
July 24–25, 2026Spikes included 16,000 attempted extraction-pattern requests involving more than 4,000 users.
July 28, 2026Related prompt-pattern activity across a cluster of more than 15,000 users had been disrupted.

The cross-conversation technique OpenAI described

OpenAI described an attempt to copy encrypted reasoning from one conversation and ask a model in another conversation to decrypt and transcribe it. The reported approach relied on manipulating model interactions, rather than breaking into the systems that store conversations.

OpenAI said the operators did not break its encryption, compromise a database, or directly access stored user conversations.

OpenAI’s response and its attribution to Moonshot AI associates

OpenAI said it banned or restricted fraudulent accounts, strengthened signup and infrastructure controls, expanded monitoring, and added protections for hidden reasoning. It also described checks intended to detect and hold streamed output that might expose reasoning, along with information sharing through the Frontier Model Forum and government partners.

OpenAI attributed a core cluster of activity to individuals associated with Moonshot AI. It said it could not determine whether all the operators it observed came from a single actor. The account concerns a separate episode from the U.S. allegations about AI-model distillation discussed in earlier coverage.