OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
A flaw in OpenAI, Anthropic, and Google's API implementations allowed researchers to extract internal reasoning and secrets—including API keys and passwords—from session logs, as encrypted reasoning objects could be replayed across different sessions.
A newly disclosed flaw in OpenAI, Anthropic, and Google APIs allowed weaker AI models to recover internal reasoning and secrets from session logs, including API keys and passwords. The vulnerability affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another. This enabled the extraction of sensitive data from stronger models' reasoning processes.