OpenAI says it shut down a coordinated adversarial distillation campaign targeting its models' protected reasoning in July 2026, but researchers demonstrated the same attack technique continued working on Microsoft Azure for weeks afterward. The attackers used encrypted reasoning packets from one conversation to decrypt hidden model thoughts in separate conversations, exploiting shared encryption keys across sessions and users.