OpenAI and Anthropic patched replay extraction on their APIs, but Azure-hosted models remain vulnerable

dyn___ · x · 2026-10-01

A security researcher shared the disclosure timeline for a model replay-extraction vulnerability: a September 13 audit found the attack blocked on direct OpenAI and Anthropic APIs, but still working against OpenAI models hosted on Azure, including Opus 4.8.

The core issue is inconsistent defenses across serving platforms: the same models are protected on first-party APIs but exposed via cloud providers, so your protection depends on where you call them from. The poster criticizes labs for patching only their own APIs while leaving cloud partners exposed.

Original post →

More from Safety

Safety channel →