Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

OpenAI reveals ‘novel’ encryption bypass used in distillation attack 

Дата публикации: 30-09-2026 22:17:34

The company said individuals associated with Chinese company MoonshotAI were behind parts of the attack, but did not offer hard evidence for the claim.
The post OpenAI reveals ‘novel’ encryption bypass used in distillation attack  appeared first on CyberScoop.


Основное содержимое страницы с новостью.

OpenAI said it disrupted a “coordinated campaign” to distill and extract reasoning capabilities from its AI models, pointing the finger at a Chinese rival.

On Wednesday, OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar “relevant extraction pattern.” The number of suspicious users had climbed to 15,000 by July 28, when OpenAI said it “fully disrupted” the operation.

The company called the attackers’ method “novel.” They copied encrypted reasoning data from one conversation, then asked the model in a separate conversation to decrypt the content and transcribe it in plain text. Outside researchers reported a similar vulnerability to OpenAI in August.

“The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” OpenAI wrote in an unsigned blog post. “Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.”

OpenAI said it’s unclear whether all the activity is related, but individuals working on behalf of Moonshot AI, a China-based rival AI company that has, in the past, been accused of distilling U.S. models, were behind a “core cluster” of the activity.

OpenAI’s blog post does not cite any technical evidence or reasoning for its attribution. Moonshot AI’s Kimi is one of several Chinese open-source AI models that are offering users and organizations good-enough performance for free or at a low cost.

American AI companies and the U.S. government have accused Chinese companies like Moonshot AI of conducting “systematic” distillation attacks on their latest models. Cybersecurity experts at Google and other cybersecurity firms say Chinese companies rely on black or gray markets to acquire thousands of individual accounts for models like Claude and ChatGPT. They then flood those models with millions of prompts and data requests that help them copy model capabilities and training data.

OpenAI told CyberScoop that it was not sharing any additional information “for security reasons.” CyberScoop has reached out to Moonshot AI for further comment.

According to OpenAI, the same vulnerability exists in other AI models, and it has shared information about the incident with groups like the Frontier Model Forum.

Beyond banning offending accounts, OpenAI said it improved signup and infrastructure controls and expanded network monitoring. It also fixed a bug that allowed users to take encrypted data from one conversation and decrypt it in another. 

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1AI policy circles targeted in China-linked phishing operation013.7601-10-2026
2AI giants probing tens of thousands of security incidents – Axios09.8327-09-2026
3The legal questions raised by agentic AI hacks08.7502-10-2026
43 guys hacked OpenAI using a rival Anthropic model. Here's what to know.011.7222-09-2026
5Fox News: Китайская нейросеть описала создание биооружия и сценарии убийств08.4402-10-2026
6OpenAI apologies for Australian government website hack, pledges to rebuild trust07.0329-09-2026
7OpenAI AI agent breaches internet-free sandbox, sends 20 web queries013.5827-09-2026
8OpenAI hack sparks further concern over AI models going rogue07.0128-09-2026
9OpenAI says its models engaged with US government websites in misbehavior disclosure05.9226-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 6.69. Источник: www.cyberscoop.com.