OpenAI Blocked 15,000-Account Bid to Steal Model Reasoning — Azure Stayed Exposed
OpenAI disrupted a 15,000-account campaign to steal hidden model reasoning, tied partly to Moonshot AI — yet the same attack worked on Azure for weeks, even on GPT-6 Astra.
Updated
Why it matters
- OpenAI says it stopped a coordinated campaign of more than 15,000 accounts trying to extract its models' hidden reasoning.
- OpenAI ties part of the activity to people connected to Moonshot AI.
- Researchers found the same attack kept working on Microsoft Azure for weeks.
- The extraction trick remained effective even against the new GPT-6 Astra.
- OpenAI's protections do not currently extend to cloud platforms that resell its models.
OpenAI says it stopped a coordinated campaign in which more than 15,000 accounts tried to copy the hidden reasoning of its models. The company ties part of that activity to people connected to Moonshot AI. But outside researchers found that the same attack kept working on Microsoft Azure for weeks — including against the new GPT-6 Astra.
That gap is the story. OpenAI's defenses appear to cover its own service. They do not, so far, extend to the cloud platforms that also sell its models.
What actually happened?
According to OpenAI, attackers operated at scale. The company says it identified and disrupted a coordinated effort involving more than 15,000 accounts. Each account, in aggregate, was aimed at one goal: extracting the hidden chain-of-thought reasoning that OpenAI's models produce before answering.
This reasoning is not meant to be visible to users. It is the internal scratchpad — the step-by-step logic a model follows to reach a conclusion. Protecting it matters to OpenAI for competitive reasons: the reasoning traces are among the most valuable intellectual property in a frontier model, because they reveal how the system thinks, not just what it says.
OpenAI also drew a connection between part of the campaign and individuals linked to Moonshot AI, the Chinese AI company behind the Kimi line of models. The company did not, based on the available reporting, describe Moonshot itself as directing the operation — it tied the activity to people connected to the firm.
Why did the attack still work on Azure?
Here the account splits. OpenAI says it shut the campaign down. But researchers found the same extraction technique remained effective on Microsoft Azure — the cloud platform where customers can run OpenAI's models through Azure's own API infrastructure.
The exposure persisted for weeks. It worked even against GPT-6 Astra, the newest model in OpenAI's lineup. In other words, a technique that OpenAI detected and blocked on its home turf continued to succeed on a partner platform that sells access to the same underlying models.
The implication is structural. OpenAI builds the models. Microsoft distributes them. When a new attack pattern emerges, each platform's defenses apply only to that platform. A block on OpenAI's API does not automatically propagate to Azure, and the researchers' findings suggest it did not in this case.
Why does hidden reasoning matter so much?
The chain-of-thought output of a frontier model is a double-edged artifact. Show it to users and you improve transparency. Hide it and you keep a competitive moat.
OpenAI has chosen to withhold reasoning traces from users of its advanced models, arguing that exposing them would make it trivial for competitors to distill the model's capabilities — effectively copying the model's trained behavior without paying to train it. An extraction campaign of this scale is precisely the threat that policy is designed to counter.
Fifteen thousand accounts is not a lone researcher probing an edge case. It is industrial-scale harvesting, coordinated across many identities, likely to evade per-account rate limits and detection heuristics.
What does this reveal about the cloud model business?
The commercial stakes are straightforward. OpenAI's models are sold through at least two doors: OpenAI's own API and products, and Microsoft Azure's OpenAI Service. Enterprises often choose Azure for compliance, existing contracts, and integration with Microsoft's cloud.
This incident shows that the two doors do not have identical locks.
If a defense exists only on OpenAI's side, then Azure becomes the softer target — same models, weaker protections. Attackers who cannot get through one door try the other. Researchers demonstrated exactly that, running the same trick against Azure for weeks after OpenAI said it had stopped the campaign.
For enterprise buyers, the lesson is uncomfortable. Choosing a deployment platform is now also a security decision, not just a procurement one. The model may be identical; the protections around it are not.
Who is Moonshot AI, and why does the attribution matter?
Moonshot AI is one of China's most prominent AI startups, known for its Kimi family of models. OpenAI linking part of the 15,000-account campaign to people connected to the company escalates an ongoing contest over model IP between U.S. and Chinese AI labs.
Distillation — using a frontier model's outputs to train a cheaper replica — has become a central concern for OpenAI and its peers. It is one reason the company limits what it exposes, including reasoning traces. Attribution like this, even partial, signals that OpenAI is watching for organized attempts, not just casual misuse.
What happens next?
The open question is whether OpenAI and Microsoft will align their defenses. OpenAI has shown it can detect and disrupt this class of campaign on its own platform. The researchers' Azure results show the protection does not travel with the model weights.
Until extraction defenses are matched across every platform that hosts a frontier model, the weakest distribution channel will define the effective security of the model itself.
Original: openai.com
More from Sophie Lindqvist
Show full bio
Staff writer covering marketplaces and e-commerce at AI In Context.
191 articles