News · curated 1 Oct 2026

Disrupting a coordinated model-distillation campaign

Coverage timeline

discovered openai.com primary 1 Oct 2026thehackernews.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

OpenAI's disclosure shows adversarial distillation is a cross-model security challenge where attackers can reproduce protected reasoning at scale—potentially stripping safeguards and transferring advanced capabilities—making it a concern for any operator of frontier LLMs.

OpenAI said it identified and disrupted a coordinated adversarial-distillation campaign that manipulated model interactions to extract protected reasoning from its models, attributing a core cluster of the activity to individuals associated with Beijing-based Moonshot AI (developer of Kimi). Operators did not breach encryption or databases but used novel extraction patterns—including copying encrypted reasoning from one conversation and asking a model in another to decrypt and transcribe it—peaking at 16,000 requests from over 4,000 users on July 24–25, 2026, before disruption by July 28.