OpenAI pins its reasoning-theft campaign on Moonshot AI accounts

Share
OpenAI pins its reasoning-theft campaign on Moonshot AI accounts

Two labs shipped defenses against how AI gets copied today — one against stealing a model's reasoning, one against misusing AI-designed proteins — while Reddit slammed the door on the bots doing the copying.

OpenAI says a cluster of accounts tied to Moonshot AI spent July pulling protected reasoning out of its models at scale. In a Wednesday post, OpenAI said the campaign started July 1, spiked on July 24–25 with 16,000 extraction requests from over 4,000 accounts, and was tied to a wider cluster of more than 15,000 users before it fully disrupted the activity on July 28. The operators never broke OpenAI's encryption or touched a database — instead they copied encrypted reasoning blocks out of one conversation and asked a model in another conversation to decrypt and transcribe them. OpenAI attributes "a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi"; that attribution is OpenAI's own claim, not an independently verified finding, and the company concedes not all the operators were necessarily one actor. What makes this more than a press release: independent researchers had already documented the attack class in an August paper — which OpenAI links and confirms — showing encrypted reasoning traces can be replayed across sessions and models, so the fix has to be an industry habit, not a single vendor patch. OpenAI says it has shared the findings through the Frontier Model Forum and government channels. Reasoning traces are the most expensive artifact a lab produces; if they flow freely into a competitor's training set, the safety safeguards baked into the original model don't come along for the ride.


Google DeepMind is watermarking AI-designed proteins before the designs ever leave the computer. The new SynthID Bio family embeds invisible, verifiable watermarks into generated protein sequences and structures, and it arrives with a peer-reviewed Nature paper plus wet-lab validation: watermarked binders for three targets — VEGF-A, the SARS-CoV-2 receptor-binding domain, and PD-L1 — matched their unwatermarked counterparts on hit rate and binding affinity, with near-perfect detection accuracy. In other words, provenance tracking that doesn't cost the design any function, which is the whole trick — a watermark that weakens the protein is a watermark nobody will adopt. The caveats are real: this is proof-of-concept scale, and the paper's own adversarial test shows deliberate resequencing can cut detection sharply unless filtering is applied (estimated hit rates of 97%, 70% and 66% with filters versus 33%, 20% and 3% without, depending on target). DeepMind is open-sourcing the code, weights, and in-vitro data. As biosecurity people have argued for years, the hard part of AI biology isn't generating designs — it's knowing where a design came from after it's out.


Reddit is shutting off RSS feeds and public API access, and it says AI bots are the reason. RSS dies November 13 — Reddit's wording is that feeds have become "a common surface for large-scale scraping and automated abuse" — and all remaining public API access ends March 2027, after unregistered apps start losing access on January 12, 2027. Old Reddit gets locked to logged-in moderators and accounts that used it within the last six months. Reddit is blunt that there is no replacement for RSS feeds outside the communities you moderate, but the economics explain the rest: its non-advertising "other revenue" — essentially AI licensing — grew 24% year over year to $43 million in Q2. A data set that now pays is a data set that stops being free, and AI assistants that answer questions from Reddit threads will need a commercial deal to keep doing it.

What to watch: whether Moonshot AI responds to the attribution, and whether other frontier labs report similar extraction campaigns now that OpenAI has lit the fuse.

Is reasoning-trace theft now the front line of model competition? Tell us in the comments.

Sources: OpenAI · wccftech · Stealing Reasoning Traces from Proprietary LLM APIs (arXiv) · Google DeepMind · Nature · Ars Technica · TechCrunch · The Verge