Detected, disrupted, and publicly disclosed the campaign; attributed a core cluster to Moonshot-linked individuals; deployed mitigations (improved signup controls, expanded network monitoring, fixed the cross-conversation transfer bug) and shared findings with the Frontier Model Forum and government channels
Beijing-based developer of the Kimi model family; the entity OpenAI, Anthropic, and the White House accuse of running or benefiting from reasoning-extraction and distillation campaigns against US frontier models
Previously accused Moonshot AI (tracked internally as threat cluster GTG-16002) and Alibaba of using its Claude model to train their own AI systems; its own models, up through Sonnet 5, were separately found vulnerable to the same extraction technique on Azure
Cloud platform hosting OpenAI and Anthropic models where the reasoning-extraction technique remained exploitable for weeks after direct-API fixes, patched only on September 27-28, 2026
WH
White House Office of Science and Technology Policy
Publicly accused Moonshot AI of distilling Anthropic's 'Fable' model to build Kimi K3 and alleged use of smuggled Nvidia GB300 chips, escalating the dispute to a government-level national-security accusation