The extracted reasoning traces provide high-quality training signals for model distillation — the practice of using a stronger model's outputs to train a smaller, cheaper competitor model . This technique is at the center of a heated controversy surrounding Chinese AI labs:
However, the evidence is not definitive. Researchers including Braden Hancock (Laude Institute) and Nathan Lambert (Allen Institute for AI) argue that distillation alone cannot explain Kimi K3's full capabilities. A widely circulated PDF claiming proof of chain-of-thought distillation was criticized for combining a limited experiment with unsupported claims .
The flaw introduces multiple concrete risks beyond intellectual property theft:
All three companies were contacted by the 'Stolen Thoughts' researchers ahead of publication. According to reporting, OpenAI, Anthropic, and Google blocked the cross-model reasoning attack after being notified. Specific details of their mitigations were not fully disclosed in published sources, but the vulnerability was confirmed to exist across all three providers' APIs before patching . The attack being 'blocked' suggests the companies implemented server-side fixes — likely restricting the reuse of encrypted reasoning blocks across different model contexts or accounts
.
Anthropic had already been publicly battling distillation at scale, reporting the 24,000 fraudulent accounts and 16 million exchanges used by Chinese labs to extract Claude outputs .