September disclosure describes July activity
OpenAI disclosed a coordinated attempt to extract protected internal reasoning from its models on September 30. It attributes a core cluster to individuals associated with Moonshot AI, the company behind the Kimi model. OpenAI says it remains unclear whether all operators belonged to one actor.[1], [2]
The earliest activity began on July 1, according to OpenAI. It spiked on July 24 and 25 with 16,000 requests from more than 4,000 users. The company says it disrupted a related cluster of more than 15,000 users by July 28. Those figures count attempted extractions, not necessarily successful ones.[1]
