OpenAI announced it has halted a coordinated campaign to extract its models' internal reasoning chains, a process known as distillation that allows competitors to copy capabilities. However, new research reveals that while the company’s direct API is now protected, the same extraction technique remains effective on Microsoft Azure, highlighting a significant gap in cloud-level security.
What Happened
According to OpenAI, the extraction activity began at low volume on July 1 and spiked to 16,000 requests from over 4,000 users on July 24 and 25. The company identified a network of more than 15,000 accounts using related patterns and stated it had fully shut them down by July 28. OpenAI linked a core group behind the activity to individuals associated with Moonshot AI, the developer of the Kimi language model, though it noted it is unclear if all actors trace back to a single source.
The attack exploited a vulnerability where encrypted reasoning packets from one conversation could be moved to a separate session and decrypted by a weaker, cheaper model from the same family. This method, demonstrated by researcher Joachim Schaeffer and his team, allowed attackers to pull out hidden thoughts word for word. OpenAI credited the researchers for identifying the issue and confirmed the attack paths were real, leading to faster countermeasures.
Why It Matters
Distillation involves one model learning from another’s full output, including intermediate steps that are often omitted from the final answer. These steps are valuable because they can help recreate a model’s capabilities. OpenAI warns that these attempts are likely to grow more sophisticated as leading models improve and more players seek cost-effective ways to copy advanced behaviors.
The incident underscores a critical discrepancy in protection across different platforms. On September 13, researchers found that while the attack was blocked on OpenAI’s and Anthropic’s own APIs, it still worked on Microsoft Azure against every OpenAI model tested, including the new GPT-6 Astra, and against Anthropic models up to Sonnet 5. A second, simpler method involving a virtual notepad also successfully extracted reasoning from most models, except for Opus 5, Fable 5, and Fable 5.1.
Schaeffer argues that piecemeal fixes are insufficient because attackers can simply choose the route with the weakest defenses. The researchers suggest that cloud providers hosting reasoning models should be required to enforce equivalent protections to prevent open backdoors that could effectively sidestep export controls at the API level.
The Bottom Line
OpenAI has tightened its own API security by banning fraudulent accounts and screening streamed outputs, but the vulnerability persists on third-party cloud platforms like Azure. The company acknowledges that models hosted by partners need the same level of protection as its own services, indicating that the work to secure the entire ecosystem is not yet finished.