OpenAI said it had identified and halted a coordinated operation by more than 15,000 external users attempting to extract hidden reasoning from its models, linking the effort to the Chinese Moonshot AI initiative.

OpenAI announced it had uncovered and stopped a massive coordinated effort by more than 15,000 external users to extract hidden reasoning pathways from its AI models, a campaign it says was tied to China’s ambitious Moonshot AI program.

Scale of the operation

OpenAI’s security team detected a pattern of repeated queries that attempted to reverse‑engineer the internal decision‑making processes of its latest models. The activity spanned weeks and involved a network of accounts that appeared to be orchestrated from outside the United States.

According to the company, the participants used a combination of prompt engineering tricks and automated scripts to probe the models for chain‑of‑thought explanations that are not normally exposed to end users.

Link to China’s Moonshot AI

OpenAI linked the operation to the Chinese government‑backed Moonshot AI initiative, which aims to accelerate the development of advanced artificial intelligence through large‑scale data collection and model training.

The Moonshot AI program, launched in 2024, has been described as a national effort to achieve breakthroughs comparable to those of leading U.S. AI labs, with a particular focus on extracting and replicating reasoning capabilities from existing models.

OpenAI’s response

In response, OpenAI disabled the accounts involved, patched the vulnerabilities that allowed the reasoning extraction, and issued a public statement warning of the risks associated with coordinated probing of AI systems.

The company also announced plans to enhance its monitoring tools and to collaborate with industry partners to share threat intelligence about similar campaigns.

  • Enhanced real‑time monitoring of query patterns
  • Stricter rate limits for high‑volume users
  • Collaboration with external security researchers
  • Public disclosure of emerging threats
“We take any attempt to undermine the integrity of our models very seriously, especially when it appears to be part of a state‑backed effort,” said OpenAI’s chief security officer.

The incident underscores the growing geopolitical competition over AI capabilities and the need for robust safeguards against large‑scale exploitation attempts.

CNBC coverage of OpenAI’s disruption of the Moonshot AI campaign