Lilith Lilith.
⌕
Editorial illustration: OpenAI shut down a 15,000-user network harvesting hidden model reasoning
Lilith illustration · editorial remix

OpenAI says it uncovered a campaign that had tried to extract protected model reasoning at scale since July 1. The incident shows that model defence now depends on more than encryption: providers must also connect thousands of apparently separate interactions into one attack.

Two days in July exposed a network of more than 15,000 users

The activity began at low volume on July 1. On July 24 and 25, OpenAI observed 16,000 requests using the relevant extraction pattern from more than 4,000 users. Its wider investigation linked related prompt patterns to a cluster of more than 15,000 users, which the company says it had fully disrupted by July 28.

According to OpenAI, the operators did not break encryption, compromise a database or access stored customer conversations. They manipulated model interactions so protected reasoning could be reproduced in a visible form. The company also closed a replay path that had allowed someone already holding another user's encrypted reasoning to recover its contents.

Coordinated accounts became the weak point, not one clever prompt

OpenAI attributes a core cluster of the activity to people associated with Moonshot AI, the developer of Kimi. It also states that it cannot determine whether every operator it observed belonged to one actor. This is therefore OpenAI's attribution of part of the campaign, not an independently settled finding about the entire network.

The practical lesson reaches beyond one competitor. When extraction is distributed across thousands of identities and several services, protecting model intellectual property becomes an abuse-detection problem spanning accounts, organisations and providers. A per-account limit sees only small fragments of the operation.

The disclosed numbers measure traffic, not stolen capability

OpenAI reported request and user counts, but did not quantify how much protected reasoning was successfully recovered or whether it improved another model. The volume of traffic alone cannot establish the amount of capability transferred.

The company also has a commercial interest in drawing a firm boundary around unauthorised distillation. Distillation itself is a legitimate training method. The relevant line here is the coordinated evasion of controls, manipulation of protected reasoning and breach of service terms.

The next campaign will test intelligence sharing between providers

OpenAI banned or restricted fraudulent accounts, tightened signup and infrastructure controls, expanded monitoring and added checks for streamed output. It shared indicators through the Frontier Model Forum and government channels.

The real test will be another campaign spread across different APIs and intermediaries. If providers can correlate the same patterns across services in time, mass extraction becomes more expensive. If each provider still sees only its own account boundary, attackers can simply split the crowd into more queues.

Lilith's verdict

The model vault stayed locked, yet more than 15,000 users circled it and tried to carry the contents away in fragments. Next time, the account guard has to see the whole crowd, not inspect each pocket in isolation.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗ ↗