OpenAI says it blocked attack that stole model reasoning
What happened
On 1 October 2026, The Decoder reported that OpenAI said it blocked a distillation-theft campaign targeting model reasoning content. According to OpenAI, the activity appeared at small scale from 1 July, surged on 24–25 July to 16,000 requests from more than 4,000 users, and involved over 15,000 linked accounts; OpenAI said it shut it all down by 28 July and linked core participants to people associated with Moonshot AI. The report also noted the technique still works on Azure.
Written by AI from the reports · updated 49 min ago
Timeline
Follow the reports to see the event from each side.
- The DecoderSelectedOpenAI says it stopped a campaign to steal its models' reasoning, but the trick still worked on Azure
In distillation, one model learns from another model's full output. That includes the stronger model's complete chains of thought, not just its answers. According to OpenAI, the activity began at low volume on July 1. On July 24 and 25, it spiked to 16,000 requests from more than 4,000 users, all relying on a typical extraction pattern.
Heat of this event
Not enough continuous observations yet to draw a trend.