Cursor

Cursor Composer 2 Caught Building on Kimi K2.5 Weights

Cursor launched Composer 2 as its own model; a leaked API model ID exposed its Kimi K2.5 base within hours. Cursor's admission ignited an open-weights attribution debate.

Cursor Composer 2 Caught Building on Kimi K2.5 Weights — article cover
On this page6 SECTIONS
  1. What a Leaked Model ID Revealed
  2. The Timeline: Launch to Admission
  3. License Compliant, Trust Broken
  4. The Cost of the “Our Own Model” Narrative
  5. Lessons for Developers and Model Buyers
  6. Sources

On March 20, 2026, Cursor launched Composer 2, its flagship in-house model, promising frontier-level coding intelligence. A few hours later, a developer posting as Fynn intercepted an internal model ID in Cursor’s API traffic: kimi-k2p5-rl-0317-s515-fast. The k2p5 in that string pointed to one fact — the base of Composer 2 is Kimi K2.5, the open-weights model from Moonshot AI.

On March 22, Cursor admitted it: Composer 2 starts from Kimi K2.5’s open weights, then continues with large-scale reinforcement learning. What followed was an industry-wide fight over open-source attribution, marketing transparency, and what “our own model” is allowed to mean. The episode itself played out in days; the questions it raised will stay with the open-weights ecosystem much longer.

What a Leaked Model ID Revealed

The developer community has long practiced model fingerprinting: probing with identity questions, formatting habits, and characteristic failure modes, then matching the response profile against known models. Fynn’s find was blunter — a raw model ID leaking through API responses stripped the packaging off entirely. The RL suffix and the date stamp (0317) even exposed the training timeline.

The underlying reality: in the API era, model provenance is nearly impossible to hide for long. Weights can be rebranded, but inference infrastructure details, response fingerprints, and internal identifiers keep leaking information. Any strategy built on “nobody will find out” has a shelf life measured in hours.

The Timeline: Launch to Admission

  • March 20: Composer 2 launches, positioned in marketing as Cursor’s own model
  • March 20, evening: Fynn intercepts the model ID in API traffic; community matching confirms the Kimi K2.5 base
  • March 21: Moonshot indicates it was never informed and never compensated
  • March 22: Cursor admits Composer 2 was trained from Kimi K2.5’s open weights
  • March 23-24: Cursor executives Aman Sanger and Lee Robinson explain that roughly 25% of compute went into the base model and 75% into Cursor’s own training; later reporting describes Moonshot characterizing the relationship as a commercial partnership mediated through Fireworks AI

Kimi K2.5 is not a small model: roughly 1 trillion total parameters with around 32 billion active in a mixture-of-experts architecture, plus a 256K context window. The engineering Cursor layered on top is real — but “built from open weights” was nowhere in the launch announcement.

License Compliant, Trust Broken

Kimi K2.5 ships under a Modified MIT license: commercial use is free below a scale threshold tied to monthly active users, with attribution obligations above it. The legal analyses that followed mostly agreed Cursor stayed within the license’s terms — it requires preserving copyright and license notices, but says nothing about disclosing the base model in product marketing.

So the core of this controversy is not breach of contract; it is an expectations gap. Users assumed “our own frontier model” meant trained from scratch. The reality was open weights plus substantial fine-tuning. Both things can be true at once — a 75/25 compute split shows real investment — but the cost of nondisclosure was paid in credibility over the better part of a week.

The Cost of the “Our Own Model” Narrative

Divergence on open-source strategy was already visible at the start of the year (our opening outlook for 2026 noted reports that Meta’s Avocado might go proprietary). The Composer 2 affair puts a different question on the table: not whether to open-source, but whether to say so when you build on open weights.

For the ecosystem, the incident carries three costs. First, the commercial reputation of open-weight models gets taken hostage — if “built on open source” is treated as something to hide, genuinely open collaborations become harder to trust. Second, procurement gets harder: enterprises buying a “homegrown model” now have one more line of due diligence on training provenance and data boundaries. Third, pressure rises on license design: Modified MIT-style terms leave disclosure duties vague, and the community will quickly demand clearer norms.

Lessons for Developers and Model Buyers

Three practical takeaways for teams. First, put model-provenance disclosure on your vendor evaluation checklist — not because the law compels it, but because the cost of hiding it has now been demonstrated. Second, evaluate open weights on their own terms: K2.5’s quality as a foundation and Cursor’s packaging of it are independent questions, and conflating them leads to bad judgments. Third, assume fingerprinting becomes routine — any team serving a model externally should assume the base model’s identity will eventually be reconstructed, and design a disclosure strategy accordingly, instead of waiting to be caught.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

FOUND_THIS_USEFUL?

Support more practical AI articles, tutorials, and build notes.

BUY_ME_A_COFFEE
SHAREXEMAIL