OpenAI Caught a Hidden-Reasoning Theft Ring, but the Hole Stayed Open on Azure
OpenAI shut down a network of 15,000 accounts stealing models' hidden reasoning, but the same trick later worked on Microsoft Azure against GPT-6 Astra and Anthropic's models.
OpenAI found a network of more than 15,000 accounts on its own platform. Over the summer, they were pulling hidden reasoning out of its models — encrypted text that the company normally hides from users. At the peak, on July 24–25, that meant 16,000 requests from four thousand accounts. OpenAI links part of the network to people connected to Moonshot AI, maker of the Kimi model. OpenAI closed its own loophole by July 28. But on September 13, researchers found the same trick still working on Microsoft Azure, where copies of GPT-6 Astra and Anthropic's models were vulnerable. That hole was not closed until September 27 and 28.
What stands out to me here is not the attack itself but the gap between a model vendor and the platform that serves it. OpenAI closed the vulnerability on its own systems by July 28. On Azure, the same vulnerability was still working on September 13, and it was not closed there until September 27. When I build agents, I always check which API and which infrastructure a model is actually running through, not just the version number in its name. This case only confirms that habit. Security patches for the same model do not reach the vendor and its cloud partners at the same time. Until they do, you cannot assume a model is equally protected everywhere.
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →
Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles