API flaw lets weaker models decode hidden reasoning from OpenAI, Anthropic, Google

Researchers decoded 315,320 thinking blocks across 6,708 public agent trajectories, recovering 62 API keys, 33 passwords, 24 access tokens, and 7 private keys. The attack required obtaining an encrypted reasoning block and API access to a compatible model; mitigations have stopped the main extraction as of August 2026.
3 sources
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Claude Code 2.1.251 adds model-switch hooks, subagent streaming
- LM Studio's AI command judge starts agreeing with the defendant
- AMD releases ROCm 10.0 with native agentic AI developer experience
- UnifyGTM cuts agent model costs by 90-95%
- Criticism of AI hype: 'magical machine god' argument distracts from real harms