OpenAI says it disrupted a coordinated effort to extract protected reasoning from its models and attributes a core cluster of activity to individuals associated with Moonshot AI, the developer of Kimi. Shattered's account of the disclosure summarizes a campaign observed in July and disclosed by OpenAI on September 30.
The distinction between an allegation and a demonstrated outcome matters here. OpenAI's reported request count concerns attempted extraction, not confirmed successful extraction. Its attribution also concerns a core cluster of individuals, rather than establishing that every observed operator had the same affiliation or that Moonshot's leadership directed the activity.
What the reported numbers describe
Shattered reports that the activity began at low volume on July 1, followed by a spike on July 24 and 25 involving about 16,000 requests from more than 4,000 users. The account says OpenAI fully disrupted the campaign by July 28. Those dates distinguish the incident from the later public disclosure: this is reporting about an investigation of earlier activity, not a claim that the same campaign is still operating.
The attempted-extraction qualifier is essential. A prompt matching an extraction pattern does not establish that protected content was returned, retained or used to train another model. The account does not provide a confirmed success rate or establish that a particular Kimi release learned from extracted material.
For readers comparing the scale of incidents, requests, users and successful extractions are different units. Replacing one with another would make the story sound more conclusive than the reported evidence supports.
A behavior problem rather than a claimed database breach
The report describes operators copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe it. The reported mechanism involves a model handling content that should remain protected in a different context. It is not described as attackers independently breaking the encryption.
Shattered also reports OpenAI's statement that the operators did not compromise a database or gain direct access to stored user conversations. That limits the conclusion about this incident; it should not be turned into a broader claim that every component of a service is free of security risks.
Protected reasoning refers to intermediate work used by a model before it supplies a final response. The report explains OpenAI's concern that extracting that work could help others reproduce capabilities or expose information omitted from the final answer. That concern is the company's rationale for protecting the material, not proof that the July attempts produced a competing model.
Attribution leaves important questions open
Shattered's account notes OpenAI's uncertainty about whether all observed operators came from a single actor. Linking a core cluster to individuals associated with a company is narrower than demonstrating company authorization, funding or direction. The headline should preserve that distinction.
The report also discusses distillation as a broader training practice. The allegation concerns unauthorized extraction of protected reasoning; it should not be read as establishing that every use of a larger model to help train a smaller one is this kind of incident. Different datasets, permissions and training arrangements require their own assessment.
What developers can take from the disclosure
The account describes account restrictions, changes to technical protections and information sharing through the Frontier Model Forum. Those measures are the reported response, not an independent finding that no further extraction approach is possible.
For a team building a reasoning-based service, the incident is a reason to inspect how intermediate artifacts are stored, forwarded and interpreted across conversations. Keep a clear boundary between data that can be displayed to a user and material that should not become an instruction in a new context. The useful lesson is about maintaining that boundary; speculation about a rival's training outcomes would go beyond the public account.