# OpenAI disrupts reasoning extraction campaign that abused interchangeable encrypted reasoning traces

> OpenAI reports disrupting a distillation campaign on 28 July 2026, and a research paper shows encrypted reasoning traces in LLM APIs are interchangeable across users.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-03
Canonical: https://hisnlabs.com/en/news/openai-disrupts-reasoning-extraction-campaign-encrypted-traces

The Hacker News reported on 1 October 2026 that OpenAI had disrupted a coordinated distillation campaign aimed at its models' protected reasoning, and that OpenAI attributed a core cluster of the activity to individuals associated with Moonshot AI [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html). A research paper submitted to arXiv on 10 August 2026 describes the underlying weakness: encrypted reasoning traces that are interchangeable across sessions, users and models [[2]](https://arxiv.org/abs/2608.09867). The item concerns the security of language model APIs, which many Mac users reach through apps and agents.

## Background

The paper explains that major LLM providers return a model's step-by-step reasoning as blocks of encrypted text, which the client passes back with each subsequent request [[2]](https://arxiv.org/abs/2608.09867). Distillation, as The Hacker News describes it, is the systematic extraction of one model's outputs to train or improve another model [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html).

## Findings

According to the report, the activity began on 1 July 2026 at low volume, peaked on 24 and 25 July with 16,000 attempted requests using an extraction pattern from over 4,000 separate users, and was fully disrupted on 28 July 2026 [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html). Related prompt-pattern activity was detected across more than 15,000 separate users [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html).

The report quotes OpenAI as stating that the operators did not break its encryption, compromise a database or gain direct access to stored user conversations, and instead manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html). OpenAI banned the fraudulent accounts involved, closed a pathway that allowed users to replay encrypted reasoning to recover its contents, and added checks to detect and hold streamed output that might expose reasoning [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html).

The Hacker News states that OpenAI provided no technical evidence for the attribution to Moonshot AI, a Beijing-based company, citing security reasons, and that the article contains no response from Moonshot AI [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html). It also recalls that Anthropic accused Moonshot AI the previous month of relaying customer requests to Claude, an activity tracked as GTG-16002 [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html).

The arXiv paper reports that the encrypted blocks are fully compatible and interchangeable across different sessions, users and models, and demonstrates four attacks: model distillation by injecting encrypted traces into weaker models, data extraction, exposure of hidden hazardous content, and invisible prompt injection into agentic systems [[2]](https://arxiv.org/abs/2608.09867). In the data extraction case, the authors recovered 367 PII artifacts and 182 credentials from 315,320 reasoning blocks scraped from public repositories [[2]](https://arxiv.org/abs/2608.09867). The paper states that the research included responsible disclosure and proposes cryptographic and system-level mitigations [[2]](https://arxiv.org/abs/2608.09867).

> FireAI, the on-device firewall for macOS developed by HisnLabs, includes an optional AI model that runs only on the Mac after a one-time download. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

The campaign targeted a provider's model outputs, not the devices of its users, and the sources do not report that any user's conversation was exposed in it [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html). The paper is relevant to people who use AI agents because one of its four attacks is invisible prompt injection into agentic systems, and because it found credentials and personal data in reasoning blocks that had been published in public repositories [[2]](https://arxiv.org/abs/2608.09867).

## Recommendations

1. Keep provider API keys out of repositories and shared logs, and revoke any key that was published.
2. When storing or sharing logs of AI sessions, remove reasoning blocks and other provider-returned fields that the application does not need.
3. Review the permissions given to an AI agent, since the paper includes an attack against agentic systems.
4. Follow provider announcements about changes to reasoning handling in the APIs in use.
5. For a team that builds on these APIs, read the paper’s proposed mitigations before designing session storage [[2]](https://arxiv.org/abs/2608.09867).

## Relevance to FireAI

FireAI does not operate or protect a model API. On a Mac, it identifies an app by its code signature and applies [per-app rules](https://hisnlabs.com/en/docs/per-app-rules) to each connection, and the [Agent profile](https://hisnlabs.com/en/docs/agent-profile) flags a first-ever destination or an upload spike from agent apps such as Claude Code and Cursor, using only host names and byte counts. FireAI's own optional [on-device AI model](https://hisnlabs.com/en/docs/on-device-ai-model) is downloaded once from Hugging Face and then runs only on the Mac.

FireAI does not see inside an encrypted connection, so it cannot read a reasoning block, a prompt or a model response. It does not detect distillation, does not control what a provider returns, and does not stop an authorised account from sending requests to an API.

> A model API is reached over the network like any other service. FireAI asks before an app contacts a destination it has no rule for, and keeps the list of what each app reached. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The campaign account rests on The Hacker News's summary of OpenAI's statement, which this item could not fetch directly [[1]](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html). The attribution to Moonshot AI is OpenAI's assessment without published technical evidence. The paper is a preprint; this item relied on its abstract and did not verify its results independently [[2]](https://arxiv.org/abs/2608.09867). The sources do not state which providers have changed their APIs beyond the OpenAI measures listed.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [The Hacker News, 1 October 2026: OpenAI disrupts reasoning extraction campaign linked to Moonshot AI associates](https://thehackernews.com/2026/10/openai-disrupts-reasoning-extraction.html)
- [arXiv, 10 August 2026: Stealing Reasoning Traces from Proprietary LLM APIs (Panfilov et al.)](https://arxiv.org/abs/2608.09867)
