The AI “thinking” blocks you’re not meant to see turned out to have a shared key sitting under the hood, and that’s bad news for Moonshot.
A new study found that OpenAI, Anthropic and Google all encrypted their models’ internal reasoning with global keys rather than unique ones. So while a model like Claude Opus is trained to refuse handing over its raw thought process, researchers discovered you could just copy that encrypted block and feed it to a weaker, less guarded sibling model. Haiku, for instance, decoded Opus’s “secret” thinking without much fuss.
Beyond the obvious safety headache, that already caused real damage. Public developer logs scanned by researchers coughed up 367 pieces of personal data and 182 exposed credentials that people assumed were sealed away inside these blocks.
Then things got properly interesting for Moonshot. Researchers fed a mere 1 percent fragment of decoded Claude Opus 4.8 reasoning into Kimi K3, and the model’s subsequent thinking and answers shifted to match Claude’s phrasing almost instantly. Per the study, specific Claude and GPT reasoning spans are up to six orders of magnitude easier to extract from Kimi K3 than from any other open model, DeepSeek-V4-Flash included.

None of this is a signed confession, and the researchers stop short of calling it proof. But it’s landed in the middle of an already ugly spat, with a Trump administration official accusing Moonshot of quietly running NVIDIA GB300 servers, some reportedly routed through Thailand, to punch above its weight.
Moonshot’s said nothing so far. Given the numbers here, staying quiet might not cut it much longer.
For more updates like this, check out the gaming news section!
More Stories
Anthropic pays AI-Chip teachers nearly double its actual chip engineers
OpenAI Security Test Incident Reveals Two New AI Testing Cases
SAPPHIRE EDGE+ Apex Brings Faster AI Performance for Next Generation Robotics