Skip to main content
SecurityEnterpriseModels

OpenAI says it stopped a campaign to steal its models' reasoning, but the trick still worked on Azure

Source: The Decoder (opens in a new tab) · Maximilian Schreiner

Intel Summary

OpenAI reported stopping a coordinated campaign involving over 15,000 accounts attempting to extract the hidden reasoning processes of its models, linking part of the effort to individuals connected to Moonshot AI. However, researchers discovered that the extraction technique remained functional on Microsoft Azure for weeks, including against GPT-6 Astra, indicating OpenAI's defensive measures were not mirrored on third-party cloud hosting platforms.

Why It Matters

The persistence of the extraction vulnerability on Microsoft Azure highlights significant security parity gaps between direct model API endpoints and partner cloud deployments. For enterprise buyers and defenders, this divergence demonstrates that vendor-level guardrails and anti-distillation defenses do not automatically protect downstream managed cloud instances, leaving proprietary model outputs and chain-of-thought logic vulnerable across partner infrastructure.

Part of an ongoing development

Source

OpenAI attributes model reasoning extraction attempt to Moonshot AI

The company attributed a portion of this extraction activity to Chinese artificial intelligence startup Moonshot AI, according to reporting from CNBC. Claims are as reported; this summary makes no determination about accuracy or significance.

Organizations & Entities

Topics