AgentsAugust 11, 2026via The Decoder
"But marinade" and leaked passwords are what researchers found in ChatGPT's hidden reasoning
Why it matters
A critical security flaw in reasoning APIs exposes both sensitive credentials and the hidden behavior of AI systems, threatening production deployments and raising questions about what reasoning layers are actually doing versus what users are told.
Key signals
- Vulnerability affects OpenAI, Anthropic, and Google APIs
- Researchers extracted encrypted reasoning traces and moved them between models
- Public session scan found dozens of exposed passwords and API keys
- Reasoning summaries shown to users hide actual model behavior
- Security issue in reasoning layer APIs — affects agent reliability and trust
The hook
Researchers found dozens of leaked passwords and API keys in ChatGPT's reasoning traces — plus a vulnerability that lets attackers extract encrypted reasoning across OpenAI, Anthropic, and Google models.
Security researchers found a vulnerability in the APIs of OpenAI, Anthropic, and Google that lets them extract encrypted reasoning traces and move them between models. A scan of public sessions turned up dozens of passwords and API keys. The traces also show that the reasoning summaries users see of…