OpenAI says it stopped a campaign to steal its models' reasoning, but the trick still worked on Azure
OpenAI blocked 15,000 accounts stealing its reasoning. Microsoft Azure users kept the attack working for weeks.

Why it matters
A coordinated campaign to extract proprietary model reasoning from OpenAI was disrupted on OpenAI's infrastructure but continued succeeding on Microsoft Azure, exposing a protection gap between direct API access and cloud-platform deployments. The finding raises questions about model-access governance and whether cloud providers inherit responsibility for API security.
The key facts
6 to knowMore than 15,000 accounts participated in coordinated extraction campaign
OpenAI attributes part of activity to people connected to Moonshot AI
Attack method remained effective on Azure for weeks after OpenAI's claimed disruption
Attack successful against GPT-6 Astra on Azure
OpenAI's protections do not extend uniformly to cloud platforms reselling its models
Researchers independently verified the continued vulnerability
Go to the source
The Decoderthe-decoder.com
Publisher excerpt: OpenAI says it stopped a coordinated campaign in which more than 15,000 accounts tried to copy the hidden reasoning of its models. The company ties part of the activity to people connected to Moonshot AI. But researchers found that the same attack kept working on Microsoft Azure for weeks, even…