< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-12T17:17:38+05:30

Security Flaw in OpenAI, Anthropic, and Google APIs Enables Decoding of AI Reasoning Traces

A security flaw in OpenAI, Anthropic, and Google APIs allowed recovery of encrypted reasoning blocks, exposing secrets like API keys and passwords through replay attacks. Researchers demonstrated methods to decode stronger models' reasoning using weaker models, leading to mitigations that stopped the attacks as of August 2026.

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords.

The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing,

Read original article

*** END OF TRANSMISSION ***