OpenAI says it shut down a coordinated effort to extract hidden reasoning from its models, but independent researchers found that the same technique remained usable through Microsoft Azure after OpenAI’s own endpoint was patched. The gap shows how one model can have different protections depending on who serves it.

OpenAI traced related activity to more than 15,000 accounts. On July 24 and 25 alone, over 4,000 users made 16,000 requests matching a known extraction pattern. The company described them as attempted extractions and linked a core group to people associated with Moonshot AI, while acknowledging that not every account necessarily had one source.

The technique moved encrypted reasoning data between conversations, then used a cheaper related model as a “decryption oracle” to print the hidden steps. OpenAI says it tightened account creation, blocked reuse of reasoning packets and added streamed-output screening.

Researchers retested on September 13 and reported that extraction was blocked on OpenAI’s and Anthropic’s own APIs but still worked against their models on Azure, including GPT-6 Astra. OpenAI protections reached that endpoint on September 27, according to the reported timeline. The episode suggests model vendors and cloud partners need synchronized defenses; otherwise attackers can choose whichever hosting route remains weakest.