AgentsThe story, in brief

"But marinade" and leaked passwords are what researchers found in ChatGPT's hidden reasoning

Researchers found dozens of leaked passwords and API keys in ChatGPT's reasoning traces — plus a vulnerability that lets attackers extract encrypted reasoning across OpenAI, Anthropic, and Google models.

Illustration of a transparent lens revealing connected networks across layers of paper.
Exploring the next frontier of AI research.AI illustration by KeyNews
The KeyNews take

Why it matters

A critical security flaw in reasoning APIs exposes both sensitive credentials and the hidden behavior of AI systems, threatening production deployments and raising questions about what reasoning layers are actually doing versus what users are told.

The key facts

5 to know
  1. Vulnerability affects OpenAI, Anthropic, and Google APIs

  2. Researchers extracted encrypted reasoning traces and moved them between models

  3. Public session scan found dozens of exposed passwords and API keys

  4. Reasoning summaries shown to users hide actual model behavior

  5. Security issue in reasoning layer APIs — affects agent reliability and trust

Go to the source

The Decoderthe-decoder.com

Publisher excerpt: Security researchers found a vulnerability in the APIs of OpenAI, Anthropic, and Google that lets them extract encrypted reasoning traces and move them between models. A scan of public sessions turned up dozens of passwords and API keys. The traces also show that the reasoning summaries users see…
Read original report
Back to today's editionMore agents news

Keep reading

Related stories

More from Agents