Invest3 publishers3 min readPublished
OpenAI says it disrupted Moonshot-linked users trying to extract its models' protected reasoning
OpenAI says it disrupted a large-scale effort by users tied to Moonshot AI to extract protected reasoning from its models. That makes three US accusers of the lab behind Kimi K3, and the published evidence so far covers attempted extraction only.
The Investor · Invest desk

What happened
- Anthropic has separately accused Moonshot of sending nearly 300,000 requests through fraudulent accounts for distillation.
- Moonshot denies the allegations and says its results come from legitimate innovation.
- Moonshot released Kimi K3, an open-weight model with 2.8 trillion parameters, on July 16, 2026.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost Labs that pay the research and compute bill distillation lets a copier skip now also pay to find and shut down fraudulent accounts.
- exposure Any lab selling paid access to its outputs is exposed through its own customer accounts, because fake accounts and evasion tactics are the tools the allegations name.
- contradiction OpenAI's own account, a disrupted operation, supports intent more than transfer, so the claim that K3's reasoning came from US models rests on evidence no accuser has published.
- precedent A White House official naming a specific model moves distillation toward government action, though nothing in the current allegations confirms sanctions.
Distillation, as these allegations use the term, means feeding a strong model many prompts, collecting what comes back and training a rival on the results, so the copy picks up capability without paying the original's research and compute bill [11]. OpenAI and Anthropic sell that output, keeping their top models behind paid access [7]. The customer account is where they earn money. By the accusers' description it is also where the extraction happens, through fake user accounts and a range of evasion tactics aimed at both companies' models [3].
Anthropic's figure is the only count in the record: nearly 300,000 requests through fraudulent accounts [2]. That is a count of requests, not tokens. US government warnings about Chinese labs, going back to at least late 2024, have been framed in billions of tokens [9]. For 300,000 requests to return even one billion tokens, each response would have to average about 3,300 tokens [1]. The published account does not say how long the responses were.
OpenAI's version is thinner still. It says the effort was large-scale, tied to users affiliated with Moonshot and aimed at the step-by-step reasoning it treats as protected, and that it disrupted the operation [1]. OpenAI did not publish a request count or anything tying extracted output to Kimi K3's training. The word it chose also limits the charge. An operation that was stopped shows intent, or rather shows OpenAI's account of intent, and says less about what, if anything, ended up inside K3.
The case can go a few ways. If OpenAI or Anthropic produce evidence linking specific outputs to K3, Washington already has a named case: Michael Kratsios, director of the White House Office of Science and Technology Policy, has accused Moonshot of stealing from Anthropic's Fable model [4]. Crypto Briefing notes that nothing in the current allegations confirms specific action such as sanctions [12]. If the evidence stays private, the fight stays commercial, and Crypto Briefing expects the labs to keep investing in detecting and shutting down fraudulent accounts, as OpenAI says it did here [13]. Moonshot denies the allegations and says its results come from legitimate innovation [5]. DeepSeek faced similar claims before it [10].
I'd expect the commercial path in the near term, with the cost landing on the accusers. K3 has 2.8 trillion parameters and came out on July 16, 2026 [6]. It is open-weight, so outside developers can download it and run it themselves [7], and Crypto Briefing describes its coding and reasoning results as strong [8]. Whatever its provenance, that model is already in developers' hands. Meanwhile OpenAI and Anthropic are adding screening costs to the paid channel it competes with.
The counter-case is the number of accusers. OpenAI, Anthropic and a senior White House science official have now all aimed at the same company [14], and an official who has already named a model may not wait for a lab's logs before acting. Published evidence tying extracted reasoning to K3's weights, or a sanction naming Moonshot, would prove this view wrong.
What to watch
- Whether OpenAI or Anthropic publishes evidence tying specific extracted outputs to Kimi K3's training data.
- Whether Kratsios's accusation over Anthropic's Fable model becomes a sanction or other formal action naming Moonshot.
- Whether OpenAI discloses a request or token count comparable to Anthropic's figure of nearly 300,000 requests.