Friday, Oct 2, 2026
1 Azure Models Still Vulnerable to Hidden Reasoning ExtractionMSFTPVT:OPAIPVT:ANTHPVT:MNSH 🤖 AI Sep 30, 1:03 PM EDT 35/30
A September 13 audit by security researchers revealed that 'replay extraction' for AI reasoning remains functional on the Azure platform for tested OpenAI models and Anthropic's Opus 4.8. The findings show that while replay extraction is now blocked on direct APIs from OpenAI and Anthropic, the vulnerability persists in the cloud-hosting ecosystem. This discrepancy indicates that patching a primary API does not automatically secure AI models hosted on third-party infrastructure.
The discovery follows OpenAI's disruption of a coordinated campaign that began July 1 to distill its models by extracting hidden reasoning. OpenAI attributed a core cluster of the activity to individuals linked to Moonshot AI, the developer of the Kimi chatbot. The campaign peaked on July 24 and 25 with 16,000 attempted extractions from over 4,000 users, and researchers identified related activity across more than 15,000 users. Operators copied encrypted reasoning from one conversation to another, prompting the model to decrypt the content. OpenAI banned the associated accounts and closed the replay pathway on its own services, noting that recorded figures represent attempts rather than confirmed successful extractions.