tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
archive · today in ai · 2026-08-13

Researchers cracked open every lab's hidden reasoning

Archive item — written before sources were shown.

A shared encryption key let researchers decode 315,000+ reasoning blocks from OpenAI, Anthropic, and Google APIs, recovering 62 live API keys and 33 passwords.

Researchers from MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and security firm Snyk published a paper on August 10 showing that OpenAI, Anthropic, and Google encrypt each model family’s hidden chain-of-thought reasoning with a single shared key rather than a session-specific one. Because the encrypted blocks are interchangeable across sessions, users, and models from the same provider, the team could take a reasoning block produced by a stronger model and feed it to a weaker, less-guarded sibling model, which would decode and print it back out in plaintext.

The team scraped 6,708 publicly shared AI agent transcripts and used the technique to reconstruct 315,320 reasoning blocks that were supposed to stay hidden. Inside them they found 704 privacy artifacts: 62 live API keys, 33 passwords, and 24 access tokens that people had exposed to their agents and assumed were encrypted away. A cryptographer had flagged the underlying design flaw back in May; the labs reportedly saw no security implications until researchers built a working exploit.

What it means for you

The encryption on a model’s hidden reasoning was built to stop tampering, not to stop replay, and that distinction just cost real users their credentials. If your team posts agent transcripts, session logs, or eval traces publicly, do not assume a provider’s own encryption is doing your redaction for you, scan and scrub anything you paste an agent’s reasoning output into before it goes public. This is the same lesson as Claude’s new watermarking rollout and Claude shared chats that turned up in search results: providers add technical safeguards for their own purposes, and those safeguards can fail in ways that only become visible once someone builds the exploit.

sources
  1. 01Stealing Reasoning Traces from Proprietary LLM APIsarxiv.org · primary, research paper
  2. 02Single Shared Encryption Key Let Anyone Read AI Reasoning Buried in Published Logstechtimes.com · reporting
Rami Steitieh
Rami Steitieh

Builder and operator. Runs 17 content sites and Trilot LLC on the tools reviewed here.