Sam Altman's company linked the Chinese company behind Kimi with a distillation campaign aimed at leveraging the capabilities of its models to develop other AI systems
OpenAI accused Moonshot AI, the Chinese firm developing the Kimi model, of being linked to a campaign to distill its artificial intelligence systems. According to the report from the American company, this operation would have included more than 10,000 attacks aimed at extracting information about the internal reasoning of ChatGPT and other models.
The campaign is said to have started on July 1, 2026, and peaked between the 24th and 25th of that same month. OpenAI claims it was able to definitively interrupt those activities a few days later. Although it did not attribute all operations to a single responsible party, it identified a core of activity related to individuals linked to Moonshot AI.
The episode brings the focus back to the distillation of artificial intelligence models, a technique that allows for the creation of more economical and efficient systems based on the capabilities of others. However, its unauthorized use generates strong tensions among the leading companies in the sector.
According to the report, the attacks aimed to obtain protected data about the functioning of language models, including the reasoning processes that allow for solving complex problems. To achieve this, the alleged perpetrators would have employed novel distillation methods designed to extract those capabilities.
How the extraction campaign developed
OpenAI believes that these techniques could become more sophisticated with the advancement of artificial intelligence. Therefore, it warned about the difficulties in identifying and stopping operations of this scale, especially when different access methods are combined.
The company clarified that the incident did not compromise its databases, encryption systems, or other internal infrastructures. The activity would have focused on obtaining responses from the models to use them in the training of other systems, without directly accessing the servers or stealing stored information.
OpenAI did not present Moonshot AI as the absolute responsible party for all operations. In the report, it specified that it could not determine if all identified operators belonged to the same group, although it attributed a significant portion of the activity to individuals related to the Chinese company.
This is not the first time Moonshot AI has been at the center of accusations regarding the distillation of American models. In July 2026, the U.S. Office of Science and Technology Policy also pointed it out for the alleged use of training data from Claude, from Anthropic, to improve Kimi K3.
The controversy over distillation in the industry
On that occasion, the U.S. agency questioned the use of information obtained without authorization and warned about the consequences for the country's tech industry. The controversy revolves around the difference between legitimate distillation and unauthorized extraction of capabilities.
Legitimate distillation is a common practice: it allows for training smaller models based on the responses of other systems, with the aim of reducing computational costs and facilitating implementation. The problem arises when third-party models are used without permission to reproduce capabilities that their developers consider protected intellectual property.
The accusations from OpenAI reflect the tensions between companies that invest fortunes in training their models and those that seek cheaper alternatives through these techniques. While some American companies and representatives of Donald Trump's government label unauthorized practices as a form of technological theft, Jensen Huang, CEO of Nvidia, offered a different perspective by describing distillation as a mode of competition.
For now, Moonshot AI has not publicly responded to the accusations. The controversy, however, raises questions about the limits of distillation and the protection of intellectual property in a market where companies compete to develop increasingly capable and economical models.