Top StoriesNeutral
39

Researchers Expose Encrypted Inner Thoughts of Major AI Models

Security researchers found Anthropic, OpenAI, and Google all use a single global encryption key for AI reasoning tokens. By decoding 315,320 reasoning blocks, they recovered 182 credentials including 62 live API keys and 33 passwords. Providers patched servers, but historical public logs remain decodable.

DecryptJose Antonio Lanz

Quick Take

1

Researchers discovered single global encryption keys across Anthropic, OpenAI, and Google.

2

Decoded 315,320 reasoning blocks from public GitHub and Hugging Face repositories.

3

Recovered 182 credentials, including 62 live API keys and 33 passwords.

4

Providers patched servers, but historical public session logs remain vulnerable.

Market Impact Analysis

Neutral

The story concerns AI model encryption, not crypto market fundamentals, so it has little direct impact on crypto prices.

Timeframeshort

Speculation Analysis

Factuality80/100
RumorsVerified
Speculation Trigger25/100
MinimalExtreme FOMO

Key Takeaways

  • Researchers discovered single global encryption keys across Anthropic, OpenAI, and Google.
  • Decoded 315,320 reasoning blocks from public GitHub and Hugging Face repositories.
  • Recovered 182 credentials, including 62 live API keys and 33 passwords.
  • Providers patched servers, but historical public session logs remain vulnerable.
Decoded Blocks315,320from public repos
Credentials Recovered182incl. API keys and passwords
Live API Keys62exposed in logs
Passwords33among recovered creds

What Happened

Security researchers uncovered a critical flaw in AI reasoning encryption. Anthropic, OpenAI, and Google all rely on a single provider-wide key to encrypt the internal chain-of-thought. This means one key unlocks every model's hidden reasoning across each platform. The team decoded 315,320 reasoning blocks scraped from public GitHub and Hugging Face repositories. They recovered 182 credentials, including 62 live API keys, 33 passwords, and 30 personal email addresses. Providers deployed server-side patches after responsible disclosure. However, historical session logs already shared publicly remain decodable.

The Numbers

The scale of exposure is significant. 315,320 reasoning blocks were decoded. 182 credentials were recovered, including 62 live API keys, 33 passwords, and 30 personal email addresses. The team also recovered 367 personally identifiable information artifacts. The paper was submitted August 10 by MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and Snyk. The vulnerability spans three major AI providers: Anthropic, OpenAI, and Google. All three use a single provider-wide encryption key, meaning one key can decrypt reasoning across all models from that provider.

Why It Happened

The flaw is architectural. Providers bind encrypted reasoning blocks to a single ecosystem-wide key instead of per-user or per-session keys. Encrypted blocks are interchangeable across different sessions, users, and models within a provider's ecosystem. Attackers injected an encrypted reasoning block from a strong model into a weaker, less guarded model from the same provider. For example, an encrypted block from Anthropic's Claude Opus could be injected into Claude Haiku, a cheaper model lacking anti-distillation alignment, which then decoded the block verbatim. This cross-model portability allowed researchers to extract plaintext reasoning without directly attacking the stronger model.

Broader Impact

The vulnerability undermines trust in AI reasoning encryption. Historical logs remain decodable, meaning exposed credentials could still be exploited. The research suggests that provider-side encryption for reasoning models may need a fundamental redesign. Further vulnerabilities may surface as more researchers examine these systems. The incident highlights risks of sharing AI session logs publicly.

What to Watch Next

  • Monitor whether providers issue more detailed disclosures or rotate compromised credentials.
  • Watch for reports of unauthorized access using exposed API keys or passwords.
  • Track follow-up research that may reveal additional vulnerabilities in AI reasoning encryption.
Source: Decrypt

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Decrypt
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

Technology & InnovationNeutral
32

AI-Generated Pattern Evades Flock Surveillance Cameras

Bill Swearingen’s noRecognition project uses adversarial patterns to defeat AI object detection, including Flock, Axon, and Clearview. At Def Con, a wrapped Toyota Yaris went undetected by a Flock camera. The project aims to let people opt out of tracking and is crowdfunding merchandise.

85% confidence
Aug 12, 2026, 9:31 PM UTC · Decrypt
AI Encryption Flaw Exposes 182 Credentials | Bytewit