Researchers Expose Encrypted Inner Thoughts of Major AI Models
Security researchers found Anthropic, OpenAI, and Google all use a single global encryption key for AI reasoning tokens. By decoding 315,320 reasoning blocks, they recovered 182 credentials including 62 live API keys and 33 passwords. Providers patched servers, but historical public logs remain decodable.
Quick Take
Researchers discovered single global encryption keys across Anthropic, OpenAI, and Google.
Decoded 315,320 reasoning blocks from public GitHub and Hugging Face repositories.
Recovered 182 credentials, including 62 live API keys and 33 passwords.
Providers patched servers, but historical public session logs remain vulnerable.
Market Impact Analysis
NeutralThe story concerns AI model encryption, not crypto market fundamentals, so it has little direct impact on crypto prices.
Speculation Analysis
Key Takeaways
- Researchers discovered single global encryption keys across Anthropic, OpenAI, and Google.
- Decoded 315,320 reasoning blocks from public GitHub and Hugging Face repositories.
- Recovered 182 credentials, including 62 live API keys and 33 passwords.
- Providers patched servers, but historical public session logs remain vulnerable.
What Happened
Security researchers uncovered a critical flaw in AI reasoning encryption. Anthropic, OpenAI, and Google all rely on a single provider-wide key to encrypt the internal chain-of-thought. This means one key unlocks every model's hidden reasoning across each platform. The team decoded 315,320 reasoning blocks scraped from public GitHub and Hugging Face repositories. They recovered 182 credentials, including 62 live API keys, 33 passwords, and 30 personal email addresses. Providers deployed server-side patches after responsible disclosure. However, historical session logs already shared publicly remain decodable.
The Numbers
The scale of exposure is significant. 315,320 reasoning blocks were decoded. 182 credentials were recovered, including 62 live API keys, 33 passwords, and 30 personal email addresses. The team also recovered 367 personally identifiable information artifacts. The paper was submitted August 10 by MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and Snyk. The vulnerability spans three major AI providers: Anthropic, OpenAI, and Google. All three use a single provider-wide encryption key, meaning one key can decrypt reasoning across all models from that provider.
Why It Happened
The flaw is architectural. Providers bind encrypted reasoning blocks to a single ecosystem-wide key instead of per-user or per-session keys. Encrypted blocks are interchangeable across different sessions, users, and models within a provider's ecosystem. Attackers injected an encrypted reasoning block from a strong model into a weaker, less guarded model from the same provider. For example, an encrypted block from Anthropic's Claude Opus could be injected into Claude Haiku, a cheaper model lacking anti-distillation alignment, which then decoded the block verbatim. This cross-model portability allowed researchers to extract plaintext reasoning without directly attacking the stronger model.
Broader Impact
The vulnerability undermines trust in AI reasoning encryption. Historical logs remain decodable, meaning exposed credentials could still be exploited. The research suggests that provider-side encryption for reasoning models may need a fundamental redesign. Further vulnerabilities may surface as more researchers examine these systems. The incident highlights risks of sharing AI session logs publicly.
What to Watch Next
- Monitor whether providers issue more detailed disclosures or rotate compromised credentials.
- Watch for reports of unauthorized access using exposed API keys or passwords.
- Track follow-up research that may reveal additional vulnerabilities in AI reasoning encryption.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.