Overview
- OpenAI disclosed Thursday that it had identified and interrupted a coordinated campaign that began in early July and surged to about 16,000 extraction requests on July 24–25 before the company says it fully disrupted the activity by July 28.
- The attackers used many accounts and prompt techniques to coax out protected reasoning from OpenAI’s models rather than breaking encryption or accessing stored conversations.
- OpenAI tied a core cluster of the operation to individuals associated with Chinese startup Moonshot AI while noting that not all operators appear linked to a single actor and Moonshot has not responded to the allegation.
- As a defense, OpenAI says it banned or restricted fraudulent accounts, tightened signup and infrastructure controls, expanded monitoring, worked with third‑party providers to cut off related accounts, and shared findings through the Frontier Model Forum and government channels.
- The disclosure follows similar claims by Anthropic and a U.S. interagency advisory and raises the prospect of regulatory or national‑security actions that could change how firms share threat information and how foreign developers train competing models.