AnalysisPolicyAugust 12, 2026

API flaw lets weaker models decode hidden reasoning from OpenAI, Anthropic, Google

Researchers decoded 315,320 thinking blocks across 6,708 public agent trajectories, recovering 62 API keys, 33 passwords, 24 access tokens, and 7 private keys. The attack required obtaining an encrypted reasoning block and API access to a compatible model; mitigations have stopped the main extraction as of August 2026.

3 sources

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed