# The Decoder — OpenAI says it stopped a campaign to steal its models' reasoning, but the trick still worked on Azure

- Company: The Decoder (the-decoder.com)
- Announced: 2026-10-01T12:05:49+00:00
- Category: safety-policy-update
- Coverage: not counted
- Announcement: yes
- Group: announcements
- Source: https://the-decoder.com/openai-says-it-stopped-a-campaign-to-steal-its-models-reasoning-but-the-trick-still-worked-on-azure/
- Record: https://forck.live/items/15567-openai-says-it-stopped-a-campaign-to-steal-its-models-reasoning-but-the-trick
- Subject: Reporting
- Models affected: GPT-6 Astra, Sonnet 5, Opus 4.8, Sonnet 5, Opus 5, Fable 5, Fable 5.1

OpenAI reported that it detected and shut down an adversarial distillation campaign targeting the hidden reasoning of its AI models, which began in July and involved over 15,000 accounts. Researchers later found that the same attack still worked on Microsoft Azure as of September 13, extracting reasoning from OpenAI and Anthropic models hosted there, despite being blocked on the companies' own APIs. OpenAI has implemented countermeasures including banning fraudulent accounts, tightening sign-ups, and screening streamed outputs, but acknowledges that protections must extend to partner-hosted models.

## Evidence

Verbatim from https://the-decoder.com/openai-says-it-stopped-a-campaign-to-steal-its-models-reasoning-but-the-trick-still-worked-on-azure/:

> When the team tested again on September 13, the attack was blocked on OpenAI's and Anthropic's own APIs. On Microsoft Azure, it worked against every OpenAI model they tried, including the new GPT-6 Astra, and against Anthropic models up to Sonnet 5.

---

Record: https://forck.live/items/15567-openai-says-it-stopped-a-campaign-to-steal-its-models-reasoning-but-the-trick
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
