AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get tech for your team delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

OpenAI says it shut down accounts involved in attempts to extract its models’ hidden reasoning and added safeguards to its own services. Researchers later reported that a related extraction method still worked through Microsoft Azure, illustrating how protections can differ when models are hosted by partners.

OpenAI says it shut down more than 15,000 related accounts involved in attempts to extract its models’ hidden reasoning, but researchers later reported that a method for recovering that reasoning still worked through Microsoft Azure. The reports highlight a gap between protections on a model maker’s own service and safeguards applied when the same models are offered through cloud partners.

OpenAI said the activity began at low volume on July 1 and rose sharply on July 24 and 25, when it recorded 16,000 requests from more than 4,000 users following a common extraction pattern. The company said further investigation found a network of more than 15,000 accounts with related behavior, which it had shut down by July 28. A footnote in the report clarifies that these figures concern attempted extractions; they do not establish that every attempt succeeded.

OpenAI linked a core group involved in the activity to people associated with Moonshot AI, the company behind the Kimi model, but said it could not determine whether all the actors it observed came from one source. The reported technique involved copying encrypted reasoning data from one conversation and asking a model in another conversation to decrypt and reproduce it. OpenAI said it closed the flaw that allowed people to reuse and read reasoning that did not belong to them, tightened account sign-ups, and began screening streamed outputs for possible reasoning disclosure.

Researchers led by Joachim Schaeffer said in a September 13 test that the extraction was blocked through OpenAI’s and Anthropic’s own APIs but still worked on Azure for every OpenAI model they tested, including GPT-6 Astra, and for Anthropic models up to Sonnet 5. The researchers said a single attempt could recover reasoning verbatim. Their timeline says safeguards were added to the Azure endpoint for OpenAI models by September 27 and that the reported extraction could no longer be reproduced there for Anthropic models from September 28. Those results are the research team’s findings, not an independent audit described in the source material.

At a glance
updateWhen: OpenAI says it shut down the accounts b…
The developmentOpenAI says it disrupted a campaign to extract model reasoning, while researchers reported that the method remained usable on Azure until cloud-side safeguards were added.

Why Partner-Hosted Models Matter

The reports show that model security depends on where a model is served, not just on the safeguards built into its developer’s own API. If protections differ across hosting platforms, a user seeking information that one service blocks may try another route offering the same model. That can leave a gap even after the model maker has changed its own systems.

Hidden reasoning can include intermediate material that is not intended for a final user-facing answer. OpenAI says that material could help another developer reproduce a model’s capabilities through distillation, in which one model is trained using another model’s outputs. The reports do not establish how much reasoning was successfully obtained or whether it was used to train competing systems. They do raise a practical question for model developers and cloud providers: whether security measures must be applied consistently across every service hosting a model.

The researchers also described a separate, simpler way to prompt some models to write reasoning into a virtual notepad tool. They said it worked on every OpenAI model they tested and on Anthropic’s Opus 4.8 and Sonnet 5, but not on Opus 5, Fable 5 or Fable 5.1. They said the output resembled what the decryption method produced and could likely be useful for distillation. These findings make clear that a fix for one extraction route may not close other routes.

Amazon

AI model security protection tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How Reasoning Extraction Worked

In distillation, a weaker or cheaper model learns from the outputs of a more capable one. According to OpenAI, the information at issue was not limited to a model’s final answer: it included intermediate reasoning that may contain material deliberately withheld from the user-facing response. The company says access to that material could make it easier to reproduce a model’s capabilities.

The extraction approach was examined by Schaeffer and colleagues in research cited by OpenAI. Their paper described how encrypted reasoning data returned to customers could be moved between sessions, users and models from the same provider. The researchers said a cheaper model could then be used as a “decryption oracle” to print the stronger model’s reasoning. OpenAI said the researchers’ findings helped it confirm the reported attack paths and accelerate countermeasures.

OpenAI said it shared information about the issue through the Frontier Model Forum and government channels, arguing that the risk extends beyond its own models. The Decoder also noted Anthropic had recently reported similar attempts involving Chinese AI companies. That report does not by itself establish that those incidents used the same method or involved the same actors.

““We stole reasoning. Again.””

— Joachim Schaeffer, researcher

Amazon

cloud API security monitoring

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What the Tests Do Not Establish

The reported account totals describe attempted extractions, not a confirmed count of successful recoveries. The available account of the findings does not say how much reasoning, if any, was collected, who ultimately obtained it, or whether it was used to train another model. OpenAI also said it was uncertain whether all the actors it identified belonged to a single source.

The Azure findings are attributed to the researchers’ tests and timeline. The source material does not describe an independent replication, provide full technical test data, or specify whether every Azure configuration and model version was examined. It also does not establish that the reported methods were used by the accounts OpenAI shut down in July. The relationship between those accounts and the later research tests remains unclear.

It is also uncertain whether the reported fixes cover every extraction method or hosting arrangement. The researchers characterized some existing measures as piecemeal and dependent on matching specific request patterns, while OpenAI said protections are still being improved. The companies’ public accounts, as summarized in the source, do not provide a full account of ongoing mitigations across all partner platforms.

Amazon

AI model encryption hardware

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Safeguards Across Cloud Platforms

OpenAI says it expects attempts to become more sophisticated as leading models improve and more organizations seek lower-cost ways to reproduce their capabilities. Its stated response includes account controls, screening of streamed outputs and work with external forums and government channels. The source does not give a schedule for completing protections across every partner-hosted deployment.

The researchers argue that fixes need to address different extraction methods and apply to every cloud provider serving the models. Their paper further argues that providers without equivalent safeguards should not serve reasoning models, though that is the researchers’ policy position rather than a reported regulation or settled industry rule. The immediate next point to watch is whether OpenAI, Anthropic and their cloud partners publish further details about how protections are tested and kept consistent after model updates.

Amazon

AI reasoning data protection

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Did OpenAI confirm that its reasoning was stolen?

OpenAI reported a campaign of attempted extractions and said it shut down related accounts. The source clarifies that the reported request figures do not mean every attempt succeeded, and it does not quantify how much reasoning was recovered.

What did researchers report about Azure?

The researchers said their September 13 tests were blocked on OpenAI’s and Anthropic’s own APIs but still worked through Azure for the OpenAI models they tested and some Anthropic models. Their timeline says Azure safeguards were added later in September.

What is model distillation?

Distillation is a way to train a model using outputs from another model. OpenAI says hidden intermediate reasoning could be valuable in this process because it can reveal more than a final answer.

OpenAI linked a core group behind the activity to people associated with Moonshot AI, which makes Kimi. It also said it was unclear whether all the actors it observed came from the same source.

Are all cloud-hosted models protected now?

The source reports specific Azure safeguards added in late September, but does not confirm that every model, hosting configuration or extraction method is covered. OpenAI said the work remains ongoing.

Source: rss

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Best AI Automation Software For Small Businesses Compared

Compare leading AI automation tools for small businesses, focusing on features, cost, ease of use, and scalability to find the right fit.

5 Ways To Upgrade Your Home Decor With Google Search

Discover five new ways Google Search can assist with home decor, from visualizing furniture to price comparison, as announced in August 2026.

AI-Powered Ideas For Halloween Decorating

AI Halloween decorations can generate content or respond to visitors, but some use only sensors and recordings. Check features, privacy and reliability.

Best AI-Powered Marketing Automation Tools Compared

Compare leading AI marketing automation platforms to identify which best fits your business needs based on features, ease of use, cost, and integration.