OpenAI Accuses Moonshot of Large-Scale Data Extraction from GPT Models
nashnova research
OpenAI has formally accused Chinese AI company Moonshot of orchestrating large-scale data extraction from its GPT models, with peak request volumes hitting 16,000 — the most specific escalation yet in U.S. AI firms' distillation complaints against Chinese rivals.
What exactly happened?
OpenAI published a blog post on September 30 publicly naming Moonshot AI (maker of Kimi), accusing it of coordinated data extraction from GPT models starting in early July.
Request volumes peaked at 16,000 in late July. OpenAI acknowledged it cannot attribute every operator to one entity but said Moonshot-linked users played a "significant role."
This means → OpenAI has moved from anonymous hints to naming names — a clear escalation in posture.
How did they bypass the defenses?
OpenAI had already hidden its models' reasoning chains — the step-by-step logic behind an answer — showing users only the final output.
Attackers found a narrow jailbreak: they copied encrypted reasoning content from one conversation, then opened a new session and asked the model to transcribe it — yielding a server-readable version.
In plain terms = imagine photographing a locked notebook, then asking someone else to copy down the text from the photo. You never got the key, but the content leaked anyway.
An anonymous AI-lab source told Bloomberg that attack methods evolved as OpenAI adjusted its defenses. This reflects a key signal: the distilled data is genuinely useful for training — otherwise, the attackers would not keep investing effort.
Is it just OpenAI — or is all of Silicon Valley coordinating?
OpenAI, Anthropic, and Google have begun coordinating on adversarial distillation and sharing findings with U.S. government agencies.
Anthropic's threat report last month disclosed a far larger incident: Moonshot secretly routed thousands of user requests to its Claude model, passed off the responses as its own, and used them to train Kimi — involving millions of exchanges, dwarfing OpenAI's 16,000 figure.
This means → OpenAI's accusation is not an isolated event but part of a collective anti-distillation campaign by U.S. AI leaders; the three firms have built an intelligence-sharing mechanism.
The White House is involved too — what about the hardware angle?
White House tech-policy adviser Michael Kratsios stated publicly that Moonshot had accessed Nvidia Blackwell computing servers barred from sale to Chinese companies, using a "sophisticated internal platform" to extract data from U.S. models.
Bloomberg previously reported that Moonshot has a computing agreement with Alibaba, using roughly 20,000 Nvidia chips — a major component of Kimi's compute infrastructure.
In plain terms = the accusation chain has stretched from "you stole our data" to "you used hardware you shouldn't have had to steal it" — tying the distillation issue directly to chip-export controls.
What happens next?
OpenAI's national-security policy lead Caroline Zier stressed the focus is on terms-of-service violations, not open models or legitimate distillation, calling it "a shared challenge of ensuring America stays ahead."
Moonshot has not responded. Beijing has repeatedly denied distillation allegations and warned it would retaliate against any U.S. penalties.
This means → as accusations widen and more companies are implicated, the direction of U.S. AI policy toward China becomes the next critical test — whether enforcement stays at the corporate terms-of-service level or escalates to government-level sanctions remains an open question.
市场有风险,内容仅供研究参考,不构成投资建议。
