API Designs at Major AI Labs Exposed Internal Model Reasoning to Cross-Session Extraction
10 Articles
10 Articles
API Designs at Major AI Labs Exposed Internal Model Reasoning to Cross-Session Extraction
Major AI providers built encrypted reasoning objects into their APIs to maintain state across stateless calls. Those same objects turned out portable enough for weaker models to decode stronger ones’ hidden traces. Researchers recovered thousands of private artifacts this way. Their work, published in a paper titled Stealing Reasoning Traces from Proprietary LLM APIs, showed how session logs posted online could leak API keys, passwords, and toke…
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers’ reasoning APIs, where a block created in one session could be replayed into another and, during testing, even handed to a weaker model in the same provider fa…
'Inner Thoughts' of Every Major AI Model Exposed in Massive Exploit
Researchers found every major AI provider encrypts reasoning tokens with a single global key-and exploited it to decode 315,320 hidden thinking blocks from public logs, recovering passwords and live API keys along the way.
A vulnerability can be used to read balancing protocols from AI-top systems such as GPT-5 in plain text – with the help of smaller models from the same provider.
Providers of large language models hide the gradual thought processes of their models ("Chain of Thought"), in order to protect intellectual property and prevent data leaks. Researchers have now managed to crack these thought processes.
Every Major AI Lab's Reasoning Was Exposed by a Single Bad Key
Anthropic, OpenAI, and Google all encrypted their AI reasoning tokens with one shared global key, and researchers just proved that was a catastrophic design choice.Key takeawaysResearchers at the ELLIS Institute Tübingen and Max Planck Institute decoded 315,320 hidden AI reasoning blocks scraped from 6,708 public agent trajectory logs, recovering 182 credentials including API keys, passwords, and access tokens from real user sessions.All three p…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




