← Back to live feed

Friday, Oct 2, 2026

1
Azure Models Still Vulnerable to Hidden Reasoning ExtractionMSFTPVT:OPAIPVT:ANTHPVT:MNSH

A September 13 audit by security researchers revealed that 'replay extraction' for AI reasoning remains functional on the Azure platform for tested OpenAI models and Anthropic's Opus 4.8. The findings show that while replay extraction is now blocked on direct APIs from OpenAI and Anthropic, the vulnerability persists in the cloud-hosting ecosystem. This discrepancy indicates that patching a primary API does not automatically secure AI models hosted on third-party infrastructure.

The discovery follows OpenAI's disruption of a coordinated campaign that began July 1 to distill its models by extracting hidden reasoning. OpenAI attributed a core cluster of the activity to individuals linked to Moonshot AI, the developer of the Kimi chatbot. The campaign peaked on July 24 and 25 with 16,000 attempted extractions from over 4,000 users, and researchers identified related activity across more than 15,000 users. Operators copied encrypted reasoning from one conversation to another, prompting the model to decrypt the content. OpenAI banned the associated accounts and closed the replay pathway on its own services, noting that recorded figures represent attempts rather than confirmed successful extractions.

Image via @jschaeff3r on X
Earlier version from Wednesday, Sep 30
OpenAI Disrupts Moonshot AI Campaign to Extract Model Reasoning
31 tweets • 27 sources
See all 35 tweets →