Thursday, 1 October 2026 Independent review of faith, culture & public life About the review
Hochland Search

Technology

OpenAI Says It Halted Campaign to Steal Model Reasoning, but Attack Persisted on Azure

OpenAI says it stopped a coordinated campaign in which more than 15,000 accounts tried to copy the hidden reasoning of its models, with some activity tied to people connected to Moonshot AI. But researchers found the same attack kept working on Microsoft Azure for weeks, even against the new GPT-6 Astra, suggesting OpenAI's protections do not extend to cloud platforms that also sell its models.

OpenAI Says It Halted Campaign to Steal Model Reasoning, but Attack Persisted on Azure
OpenAI

OpenAI says it has stopped a coordinated campaign in which more than 15,000 accounts attempted to copy the hidden reasoning of its artificial intelligence models. The company has linked part of the activity to people connected to Moonshot AI, according to its findings. The operation targeted the internal reasoning processes that OpenAI does not expose to users, a core part of the value of its advanced systems.

But the same technique continued to work on Microsoft Azure for weeks, according to researchers. The attack remained effective even against GPT-6 Astra, the newest model in OpenAI's lineup. The persistence of the campaign on Azure indicates that OpenAI's protections do not automatically extend to the cloud platforms that also sell access to its models.

The disclosure highlights a growing tension in the artificial intelligence industry. Model developers invest heavily in safeguards designed to prevent outsiders from extracting the hidden reasoning that makes their systems valuable. Yet when those models are distributed through third-party cloud services, the security perimeter becomes harder to control. Azure, as a major cloud provider, offers OpenAI models to customers, but the responsibility for defending against such extraction attempts may not be clearly shared.

OpenAI's response focused on shutting down the accounts involved and disrupting the campaign on its own infrastructure. The company did not say whether it had coordinated directly with Microsoft to address the activity on Azure. The researchers' finding that the attack worked for weeks on Azure suggests a gap between the protections applied on OpenAI's platform and those in place on the cloud service.

The campaign involved more than 15,000 accounts, a scale that indicates a sustained and organized effort rather than isolated misuse. By targeting hidden reasoning, the attackers sought to replicate the internal decision-making of the models, which could allow them to build competing systems or gain insights into OpenAI's proprietary techniques. The connection to people linked to Moonshot AI adds a competitive dimension to the incident.

For businesses and developers who rely on OpenAI models through Azure, the news raises questions about whether their own use of the models is protected by the same safeguards. If the extraction technique worked on Azure for weeks, other customers might have been exposed to similar attempts without their knowledge. The incident also underscores the difficulty of securing AI models once they are made available through multiple channels.

OpenAI has not publicly detailed the technical nature of the attack or the specific measures it took to stop it. The company's statement that it stopped the campaign contrasts with the researchers' observation that the trick still worked on Azure. That discrepancy suggests that stopping an attack on one platform does not necessarily eliminate it elsewhere, especially when the model is hosted by a third party.

The episode comes as AI companies face increasing pressure to protect their intellectual property while expanding access to their models. Cloud partnerships are a key part of that expansion, but they also create new vulnerabilities. How OpenAI and Microsoft address the gap will be closely watched by the industry, as other model providers rely on similar arrangements.

For now, the incident serves as a reminder that security in AI is not just about building strong defenses at the source. It also depends on how those defenses are maintained across every platform where the models are deployed. Until that challenge is resolved, campaigns to steal hidden reasoning may continue to find openings.

4Views

Jana Hartmann

Author

Culture Reporter

Jana Hartmann covers public affairs, politics, business, culture and daily news for Hochland. The role focuses on verification, context, and clear explanations for readers.