Researchers discovered a significant vulnerability in APIs from Google, OpenAI, and Anthropic. This flaw allows the extraction of hidden reasoning traces from flagship models including Gemini, GPT, and Claude.
Attackers feed encrypted reasoning from a powerful model into a weaker model from the same provider. The weaker model decodes the data and outputs the reasoning in plaintext.
This technique bypasses security measures to expose API keys, passwords, and personally identifiable information. Researchers identified these leaks within publicly shared session logs.
An architectural issue prevents encrypted data from being cryptographically tied to specific users or sessions. This flaw makes sensitive data portable across a provider's entire ecosystem.