Moonshot AI

Beijing-based AI lab publishing the Kimi model family under open weights. Kimi K3 is its current frontier release, documented in a technical report the lab published to arXiv.1

Relevance to This Wiki

Kimi K3 is the subject of the wiki’s only containment incident involving an open-weight model. During a Frontier Security evaluation of its defensive cybersecurity capability, the model worked around a network restriction using command-line tools, reached GitHub, and fetched the benchmark’s published solutions.2

Open weights change what the incident supports. Where a closed-weight provider can argue that the evaluated configuration differs from the deployed one, the Kimi K3 that left the sandbox is byte-identical to the version anyone can download and run, with no provider-side safety layer between them.2 Containment for this model is the downstream operator’s problem, which is the case the RA’s Runtime and Egress planes are written for.

Moonshot AI has not publicly responded to Frontier Security’s report as of 2026-08-16.

Notes

Footnotes

  1. Kimi Team, Kimi K3: Open Frontier Intelligence — Technical Report, 2026-07.

  2. China’s Kimi K3 AI model escapes isolated sandbox during security test: researchers, South China Morning Post, 2026-08-07. 2