cd /news/ai-safety/openai-disrupts-moonshot-linked-camp… · home › topics › ai-safety › article
[ARTICLE · art-143036] src=cryptonews.net ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI disrupts Moonshot-linked campaign as AI distillation war intensifies

OpenAI said it detected and interrupted an "adversarial distillation" campaign in which users transferred encrypted reasoning information between chats and decoded it elsewhere, with the majority of the operations affiliated with Moonshot, and it responded with account penalties, suspended suspicious accounts, a strengthened registration process and expanded hidden-reasoning protections affecting all users, workspaces, enterprise organizations and model architectures. Caroline Zier, lead for strategic national security policy initiatives at OpenAI, said, "Our concern is about violation of our terms of service, not open models or legitimate distillation." Anthropic separately reported stopping five distillation processes that produced nearly 200 million illegal queries, including an Alibaba campaign of 151 million logged queries from May through July 2026 peaking at almost 3 million per day and a Moonshot AI campaign that forwarded nearly 300,000 queries from 5,000 accounts over 10 days, mostly directed at the Opus model.

read3 min views2 publishedOct 1, 2026
OpenAI disrupts Moonshot-linked campaign as AI distillation war intensifies
Image: Cryptonews (auto-discovered)

OpenAI says it has put more safeguards in place to prevent distillation

According to OpenAI, it detected and interrupted some operations in which users tried to steal hidden logic by transferring encrypted reasoning information between different chats and then decoding it in another chat.

The majority of those operations were affiliated with Moonshot. Simultaneously, other third- party researchers reported similar vulnerabilities to the company, including cross-model and data-compacting issues.

So far, the ChatGPT developer has characterized the recent event as “adversarial distillation” and warned that distilling the logic could enable opponents to mimic advanced technologies.

It added that a large-scale distillation process could dramatically shorten the time required to develop an advanced AI capability without any commitment to safety and alignment.

So far, to address the distillation trend, OpenAI has implemented account penalties, strengthened infrastructure, and pursued partnerships.

Moreover, it has even suspended suspicious accounts, strengthened the registration process and back-end security, and expanded its monitoring of the user community.

Additionally, it implemented more robust hidden-reasoning protections that affect all users, workspaces, enterprise organizations, and model architectures.

Caroline Zier, lead for strategic national security policy initiatives at OpenAI, added that they will continue to invest in stronger protections. She stated, “Our concern is about violation of our terms of service, not open models or legitimate distillation.”

Why AI model distillation is becoming a bigger concern

Model distillation allows developers to use the outputs of a more capable AI system to improve or replicate the performance of another model.

While legitimate distillation can be used to create smaller and more efficient systems, OpenAI argues that unauthorized large-scale extraction can give competitors access to capabilities that took significant resources to develop. The company said the latest campaign was particularly concerning because the actors were not simply using ChatGPT for ordinary tasks. Instead, they allegedly designed automated workflows to repeatedly query the models and transfer useful responses into other systems.

By collecting enough outputs, attackers could potentially reproduce aspects of a model’s reasoning, coding, and problem-solving capabilities without directly accessing its underlying weights or infrastructure.

OpenAI’s disclosures highlight a growing challenge for AI companies as increasingly capable models become widely accessible through APIs and consumer products. Providers must balance broad access to their systems with safeguards designed to prevent systematic extraction of proprietary capabilities.

Anthropic also identified Moonshot’s distillation campaign

In the last few months, Anthropic also discovered and stopped several cyber campaigns where malicious actors targeted Claude.

These perpetrators included suspected state-backed intelligence groups, financially motivated hackers, and political activists, with the incidents taking place between December 2025 and August 2026.

Their specific attacks aimed to harvest Claude’s high-value competencies: its logical deduction, coding, data evaluation, and automated agent workflows.

Reportedly, five different distillation processes resulted in nearly 200 million illegal queries. The bulk of the distillation queries came from an Alibaba campaign, which Anthropic characterized as the largest-ever data-harvesting effort in the corporation’s history. This particular campaign produced 151 million logged queries from May through July 2026, peaking at almost 3 million per day.

A second Moonshot AI campaign reportedly forwarded queries directly from China’s military to Anthropic. Over 10 days, the company recorded nearly 300,000 queries from 5,000 accounts, most of which were directed at the Opus model.

Moonshot has been receiving considerable attention in Washington due to the rapid pace at which it has surpassed its American rivals.

Although Beijing has already disregarded previous charges from Silicon Valley and the Trump administration regarding its data-harvesting activities, it has threatened to take counteraction in the event of any sanctions from Washington.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-disrupts-moon…] indexed:0 read:3min 2026-10-01 · —