In a company blog post, OpenAI detailed a series of events beginning July 1 with low-volume activity that escalated to high-volume spikes on July 24 and 25, during which 16,000 requests using an extraction pattern were observed from over 4,000 users. The company said it was not certain whether all operators were the same actor or whether the extraction attempts were successful.
The method involved encrypted reasoning blocks that clients send back with each request. The operators reportedly tried taking encrypted reasoning from one conversation and asking a model in a different session to decrypt it. OpenAI said encryption was not broken, but it closed a pathway that allowed replay of another user’s encrypted reasoning to recover its contents. Additional checks were added to detect streamed output that might expose reasoning, and protections were strengthened across users, workspaces, organizations, and model families. OpenAI also worked with third-party providers to disrupt accounts whose activity passed through their services.
Independent security researchers had previously reported related vulnerabilities through responsible disclosure, and OpenAI confirmed the attack paths were real. A research paper dated Aug. 10 described testing on OpenAI, Anthropic, and Google models, where a weaker model was prompted to write out encrypted reasoning from a frontier model in plain text. The researchers said that after the providers acknowledged their report, they were unable to launch the same attacks.
Anthropic, in a September 2026 report, stated that Moonshot relayed almost 300,000 customer requests using a proxy network of 5,380 fraudulent accounts within a single ten-day period. Anthropic also said Moonshot saved Claude’s reasoning signatures and used cross-session replay attacks to convert them back into full reasoning traces.
In July, Moonshot denied that its Kimi K3 model was created from a distillation of OpenAI’s models, and at the time OpenAI President Greg Brockman said it was "too early" to determine whether distillation had occurred. OpenAI said its next steps include ensuring partner-hosted deployments have the same protections as first-party tools.