OpenAI says it disrupted a large-scale effort by users tied to Moonshot AI to extract protected reasoning from its models. That makes three US accusers of the lab behind Kimi K3, and the published evidence so far covers attempted extraction only.
Perspective Coverage
8 publishers
- Builder
- Builder 33%
- Operator
- Operator 35%
- Investor
- Investor 32%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+35
- Incentives65
- Confidence60
OpenAI says 15,000 suspicious users had its models decode encrypted reasoning copied from other chats before it cut them off on July 28. The encryption held throughout, and the only barrier left was what the model would agree to decode.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 43%
- Investor
- Investor 25%
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence55
A dev.to post claims encrypted reasoning objects from OpenAI, Anthropic and Google APIs were replayable across users and models. The disclosure is thin, but the storage habit it exposes is yours.
Reality
- Evidence66
- Adoption45
- Hype gap+20
- Incentives55
- Confidence60
OpenAI has served SpaceX notice on its Cursor contract with a proposed Nov. 12, 2026 shutoff, which leaves anyone who standardized on Cursor with a dated job of naming the models each workflow needs and their substitutes.
Perspective Coverage
3 publishers
- Builder
- Builder 35%
- Operator
- Operator 28%
- Investor
- Investor 37%
Reality
- Evidence68
- Adoption20
- Hype gap+20
- Incentives75
- Confidence65
The allegation reaches Kimi's consumer output, and it arrives with two sets of numbers that do not fit inside each other. Anthropic has not dated the traffic, so nobody outside can tie it to a Kimi release.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence40
The September threat report puts 151 million Claude exchanges on 3,500 accounts Anthropic links to Alibaba, about 469 a day per account. The only figure denominated in money anywhere near it is a 2.7% share move.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 35%
- Investor
- Investor 37%
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence50
OpenAI has already paused some internal training runs and says it would slow its most advanced work if rivals matched it. Anthropic, in the same week, counted five attempts to use Claude for biological weapons research.
Perspective Coverage
13 publishers
- Builder
- Builder 28%
- Operator
- Operator 46%
- Investor
- Investor 26%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence55
Anthropic says six campaigns since February 2026 pulled reasoning transcripts out of Claude through proxy relays built on fictitious identities, stolen credit cards, and API keys harvested from legitimate companies and individuals.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence45
Anthropic's third misuse report says its 2025 Claude models sat well below the level that could help a sophisticated user with dangerous biology, and that for current models it can no longer make that assurance.
Perspective Coverage
5 publishers
- Builder
- Builder 28%
- Operator
- Operator 52%
- Investor
- Investor 20%
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence55
The Cyberspace Administration sent officials into DeepSeek and Moonshot AI to ask whether user requests were routed through Anthropic's Claude. Hong Kong investors sold the listed model developers hardest.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 30%
- Investor
- Investor 43%
Reality
- Evidence45
- Adoption40
- Hype gap+25
- Incentives70
- Confidence55
Anthropic's help center says the safety classifiers on Opus 5 and 5.5 check memory, connector output, web results and files as well as the prompt. A fallback can therefore come from any of those.
Reality
- Evidence58
- Adoption42
- Hype gap−18
- Incentives62
- Confidence62
Team Cymru says more than 10,000 proxy servers are masking malicious AI activity out of China, and that most of them run a handful of open-source gateway projects whose donors include residential proxy vendors.
Reality
- Evidence30
- Adoption40
- Hype gap+15
- Incentives55
- Confidence35
Team Cymru has handed the relay IP addresses to the affected AI providers, but the count it confirmed grew roughly sevenfold while it was still scanning, and the software running on most of those hosts is a public GitHub project.
Reality
- Evidence55
- Adoption70
- Hype gap+22
- Incentives65
- Confidence50
Scott Bessent discussed a U.S.-China channel for AI incidents up to a national security level. Analysts at CSIS and the Council on Foreign Relations told CNBC the likely output is shared definitions and a hotline, and that a deal to slow development is extremely unlikely.
Reality
- Evidence55
- Adoption15
- Hype gap+10
- Incentives60
- Confidence55
Team Cymru counted more than 10,000 self-hosted LLM gateways fronting traffic out of China. They pool accounts behind keys of their own, so the model provider logs the relay's address and never the user's.
Publishers:news.risky.biz · team-cymru.com Reality
- Evidence52
- Adoption74
- Hype gap+28
- Incentives76
- Confidence58
The Information reports that the Cyberspace Administration has questioned staff at both labs after Anthropic named seven Chinese companies for relaying customer requests through Claude. No penalty has been decided.
Reality
- Evidence52
- Adoption42
- Hype gap+8
- Incentives72
- Confidence55
Days before Trump, Xi and the big lab chiefs meet at the White House on AI policy, a Fortune essay attacks the race argument with an estimate that Chinese companies hold about 5 percent of the world's AI computing capacity.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+30
- Incentives72
- Confidence36
Pre-release testing of frontier models runs on a voluntary executive order plus a second, non-public agreement, and the enforcement Trump named is the Justice Department, without saying under what authority.
Reality
- Evidence46
- Adoption
- Insufficient
- Hype gap+22
- Incentives72
- Confidence48
The US cybersecurity agency says industrial-scale distillation is the core of China's AI strategy. Aidan Gomez, who co-wrote the transformer paper, told CNBC that Chinese models now beat the best American ones on some benchmarks.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives72
- Confidence55
Anthropic ties the traffic to DeepSeek, Moonshot and MiniMax through IP correlation, request metadata and unnamed industry partners. The DeepSeek campaign it quantifies is under 1 percent of the alleged total.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+30
- Incentives85
- Confidence55
Earlier coverage
- Resold chat logs move distillation outside the origin lab's request telemetry
Build · September 18, 2026 · 1 publisher
- Anthropic attributes 16 million Claude exchanges to 24,000 fraudulent accounts
Science · September 17, 2026 · 1 publisher
- Longer fine-tuning carries a cat-loving trait through all five distillation hops
Build · September 16, 2026 · 1 publisher
- Attackers went from stolen cloud credentials to mass credential harvest in under six hours
Leadership · September 16, 2026 · 2 publishers
- Amodei asks Beijing to pace the frontier while Washington widens its lead
Product · September 16, 2026 · 1 publisher
- Amodei's call to pace the frontier drew rejections from Beijing and Trump within two days
Security · September 15, 2026 · 2 publishers
- Google compiles a set-level search reward into a diffusion retriever that fans out in one pass
Build · September 15, 2026 · 1 publisher
- Nomic's CEO alleges startups resell frontier traces generated on lab credits
Build · September 14, 2026 · 1 publisher
- Z.ai's zero-coupon bond converts 12.5% above where the shares traded before the raise
Product · September 13, 2026 · 1 publisher
- JoyIn says it has started suing OpenAI over the distillation of its Aether model
Product · September 13, 2026 · 1 publisher
- Account metadata linked 16 air-defense suppression modules to PRC research institutions
Build · September 13, 2026 · 1 publisher
- Chinese models clear 75% of enterprise engineering tasks at a fifth of the US cost
Invest · September 13, 2026 · 1 publisher
- Swapping an LLM classifier for a frozen random forest leaves symptom patching at 19 of 20
Build · September 12, 2026 · 1 publisher
- Anthropic documents five possible bioweapons cases it cannot confirm were meant to cause harm
Product · September 11, 2026 · 7 publishers
- JoyIn dates its alien-visitor framing three weeks before OpenAI's essay
Product · September 11, 2026 · 1 publisher
- Garry Tan argues American open-weight labs should distill American frontier models
Product · September 11, 2026 · 1 publisher
- Moonshot's $50bn mark prices Kimi at 25 times a run-rate it has yet to reach
Invest · September 11, 2026 · 1 publisher
- DeepSeek reroutes V4-Pro API traffic to a smaller model on September 14
Product · September 11, 2026 · 1 publisher
- Three U.S. agencies name six China-based AI companies as distilling frontier models
Science · September 10, 2026 · 1 publisher
- Garry Tan relocates AI's moat from the model weights to the price list
Invest · September 10, 2026 · 1 publisher
- ShinyHunters affiliates escalated one stolen token to full cloud admin in about three hours
Product · September 10, 2026 · 1 publisher
- National cyber director says the US and allies are buying time for their systems to catch up
Security · September 10, 2026 · 1 publisher
- NSA, CISA and FBI ask providers to quietly route suspected distillers to weaker models
Build · September 10, 2026 · 2 publishers
- Three US agencies advise AI providers to quietly degrade answers for suspected distillers
Product · September 9, 2026 · 1 publisher
- Bessent likely to lead US delegation as US-China AI safety talks near, with standards among contested issues
Invest · September 5, 2026 · 1 publisher
- Anthropic calls Chinese AI distillation 'theft,' citing national security risks
Invest · September 3, 2026 · 1 publisher
- Eight B300s finish a 10.125-second MiniMax clip with 1.4 seconds of headroom
Build · September 1, 2026 · 1 publisher
- Meta's real announcement is the split: 30B on your GPU, everything else behind the API
Build · August 14, 2026 · 6 publishers