OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
Read original article ↗AI Summary
A vulnerability in reasoning APIs used by OpenAI, Anthropic, and Google allowed attackers to recover hidden internal reasoning and sensitive data such as API keys, passwords, and private keys from encrypted reasoning blocks. The flaw enabled cross-session and cross-model replay attacks, where encrypted reasoning objects from one session could be replayed in another, even using weaker models as 'fuzzy decoders' to extract secrets. Researchers analyzed 6,708 public agent trajectories and recovered 704 distinct privacy artifacts, including 62 API keys and 33 passwords, primarily from unsanitized published logs. While vendors have implemented mitigations, the research highlights ongoing risks from already-published reasoning blocks and the potential for invisible prompt injection attacks.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.