OpenAI says it stopped a campaign to steal its models' reasoning, but the trick still worked on Azure
OpenAI blocked a large campaign to steal model reasoning, but researchers say Azure still leaked it.
OpenAI said a distillation campaign that began July 1 spiked on July 24–25 to 16,000 requests from more than 4,000 users, part of a network of over 15,000 accounts shut down by July 28. It links a core group to people associated with Moonshot AI, maker of Kimi, and describes attempted extractions of encrypted chains of thought. Researcher Joachim Schaeffer showed those encrypted packets can be moved between sessions so a cheaper model from the same provider prints a stronger model's hidden reasoning. On September 13 the attack was blocked on OpenAI and Anthropic APIs but still worked on Microsoft Azure against every OpenAI model tried, including GPT-6 Astra, and Anthropic models up to Sonnet 5; a notepad-tool method also leaked reasoning from most of those models.