Published 9 hours ago • loading... • Updated 1 hour ago
OpenAI Reveals ‘Novel’ Encryption Bypass Used in Distillation Attack
OpenAI said the operators copied encrypted reasoning from one chat and used another to decrypt it, with 16,000 requests logged in two days.
On Wednesday, OpenAI accused Chinese developer Moonshot AI of leading a coordinated campaign to extract "hidden reasoning" from its GPT models, alleging users systematically copied encrypted reasoning chains.
This activity aligns with "adversarial distillation," a practice where developers extract proprietary outputs to train competing models; Silicon Valley and the Trump administration characterize such efforts by Chinese companies as systematic intellectual property theft.
Coordinated efforts peaked in July with 16,000 requests from more than 4,000 users, as operators bypassed defenses by copying encrypted reasoning from one conversation and using another model to transcribe it.
OpenAI responded by banning involved accounts, tightening sign-up checks, and adding protections for hidden reasoning, while sharing findings with government channels and the Frontier Model Forum.
Critics, including venture capitalist David Sacks, argue these accusations aim to justify banning open-weight models that challenge established business models, while the Chinese government has rejected the claims as unfounded.