The Digital Source For China's Tech Innovation Since 2000

Moonshot AI Of Kimi K3 Fame Tried To Crack OpenAI's Encrypted Reasoning Through 16,000 Requests, Bolstering Trump Administration's Distillation Claims

Once or twice can be a fluke, but thrice is a pattern, and OpenAI is now making sure that Moonshot AI – the lab behind the wildly successful Kimi K3 model – is tagged as a serial violator when it comes to orchestrating model distillation campaign, echoing similar calls from Anthropic and the Trump administration earlier this summer.

OpenAI: "We attribute a core cluster of the [model distillation] activity to individuals associated with Moonshot AI, the developer of Kimi"

OpenAI has just penned a post titled "Disrupting a coordinated model-distillation campaign," detailing efforts to extract "protected reasoning" from its models, with the first such "observed activity occurring in the first week of July," which is right around the time that the Kimi K3 model debuted.

OpenAI adds that the campaign was unable to "break our encryption, compromise a database, or gain direct access to stored user conversations," but did manage to manipulate "model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service."

OpenAI also found that:

  1. The campaign copied encrypted reasoning from one conversation and asked a model in another conversation to decrypt and transcribe the hidden reasoning content.
  2. "The activity began on July 1, initially at a low volume until we observed high-volume spikes on July 24 and 25 consisting of 16,000 requests using a relevant extraction pattern from over 4,000 users."
  3. The prompt-pattern activity was spread across a cluster of more than 15,000 users.
  4. OpenAI was able to fully disrupt the campaign by July 28.
  5. "We attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi."

Interestingly, it was also in late July that the current Chief Science and Technology Advisor and the Director of the White House Office of Science and Technology Policy (OSTP), Michael Kratsios, declared that the US government had "information" that Moonshot distilled its Kimi K3 model from Anthropic's models.

We also recently discussed a study where the authors fed just a 1 percent fragment of Claude Opus 4.8's decoded reasoning into Kimi K3, and the Kimi K3's subsequent thinking and final answer shifted dramatically to match Claude's style and wording.

In fact, according to the authors "specific Claude and GPT reasoning spans are up to ~6 orders of magnitude easier to extract from Kimi-K3 than from the next-closest model."

Basically, the study demonstrated that Moonshot's Kimi K3 exhibits an unusually high statistical probability of predicting and continuing Claude's text compared to other open models like DeepSeek-V4-Flash, suggesting strong behavioral compatibility with the reasoning patterns of Claude Opus.

Of course, this is not to say that Moonshot AI did not add any value on its own. After all, the Kimi K3 model is quite efficient to run on data center-scale hardware, courtesy of its dramatically reduced KV cache and built-in optimizations for per-token memory use – achieved by distributing its 896 experts across a large number of GPUs.

And, if you believe that OpenAI's newer models are resistant to reasoning extraction attempts, think again. A new study has just explained how reasoning traces from GPT-6 Astra and GPT-6.1 Sol can still be extracted via third-party APIs.

Meanwhile, Z.ai (Zhipu) was the only China-based AI lab that was able to approach Claude Mythos-level capability in Anthropic's recent testing, where its GLM-5.3 model managed to develop full control hijacks in 4 percent of the trials versus Mythos' 6 percent. This shows that China's models are increasingly gaining ground, partly through their own research and partly via distilling reasoning traces of advanced models from Anthropic and OpenAI.


Rohail Saleem Photo

About the author: Writing is my one incontrovertible passion. Over the past six years, he has authored over 2,200 distinct articles on financial and tech-related topics, spanning nearly 1 million words. And he has been a member of Wcctech mobile team since 2025.

As an alumnus of the University of Toronto, Rotman Commerce Program, I bring nuance, in-depth knowledge, and a unique perspective to every topic that I cover.

When I'm not writing, I'm traveling the world, exploring hidden confectionaries and restaurants as an aspiring food connoisseur.

Follow Wccftech on Google to get more of our news coverage in your feeds.

Other China Tech Buzz: