Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Not Ready For Prime Time: The Current State Of Legal Ethics And AI

19 minutes ago

How Much Does New York Actually Recycle? The N.Y. Comptroller Says the State Doesn’t Really Know.

21 minutes ago

U.S. CPI inflation slows to 3.4% as expected, bitcoin (BTC) holds near $64,000

39 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Wednesday, August 12
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»‘Inner Thoughts’ of Every Major AI Model Exposed in Massive Exploit
Cryptocurrency & Free Speech Finance

‘Inner Thoughts’ of Every Major AI Model Exposed in Massive Exploit

News RoomBy News Room2 hours agoNo Comments4 Mins Read2 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
‘Inner Thoughts’ of Every Major AI Model Exposed in Massive Exploit
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • A team or researchers found that Anthropic, OpenAI, and Google all use a single global encryption key for AI reasoning tokens.
  • By decoding 315,320 reasoning blocks scraped from public GitHub and Hugging Face repositories, the researchers recovered 182 credentials, including 62 live API keys, 33 passwords, and 30 personal email addresses.
  • OpenAI, Anthropic, and Google deployed server-side patches after responsible disclosure, but historical session logs already shared publicly remain decodable.

Security researchers have found a way to read the encrypted “inner thoughts” of every major AI reasoning model—and uncovered 62 live API keys and 33 passwords buried in session logs that developers had shared publicly online without knowing what was inside them.

“By decoding 315,320 reasoning blocks scraped from public repositories, we recovered 367 Personally Identifiable Information (PII) artifacts and 182 credentials,” the researchers wrote.

The paper, submitted August 10 by a team from MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and security firm Snyk, targets a specific class of AI: reasoning models. These are models that don’t just answer immediately and instead start with an internal chain-of-thought (a step-by-step scratchpad where the AI works through a problem before showing you the answer), then deliver a final response.

Anthropic, OpenAI, and Google all encrypt that hidden scratchpad. Encryption—the process of scrambling data into an unreadable code—is meant to protect the company’s intellectual property and keep sensitive intermediate reasoning away from users. The encrypted block gets passed back to the provider’s servers with every follow-up message, maintaining the conversation without storing anything on the company’s end.

One key to rule them all

The flaw is architectural. Instead of binding each encrypted reasoning block to a specific user, session, or model, all three providers use a single, provider-wide encryption key across their entire ecosystem. “These encrypted blocks are fully compatible and interchangeable across different sessions, users, and even different models within a provider’s ecosystem,” the researchers wrote.

That means a block of encrypted reasoning from Claude Opus 4.8—Anthropic’s flagship model—can be injected into Claude Haiku 4.5, a cheaper, less guarded sibling without breaking Anthropic’s rules. Haiku lacks the anti-distillation alignment (safety training specifically designed to stop a model from transcribing its own reasoning on command) that Opus has.

Tell Haiku to read out the encrypted block verbatim, and it does. “By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly,” the paper states.

“Cross-model portability means Haiku 4.5 can read Opus 4.8’s thoughts,” lead researcher Alexander Panfilov wrote on X. The same attack reproduced across OpenAI’s GPT-5.6 family and Google’s Gemini model lineup. No special access required—standard API access (the connection developers use to build applications on top of AI models) was sufficient to execute it.

We can finally talk about it:

We found a way to extract hidden reasoning of frontier models using a vulnerability in the APIs of every frontier AI company.

We verified that our reasoning token count matches billed API thinking tokens 1:1 for most of the prompts we queried. pic.twitter.com/S7wN8aP3X7

— Alexander Panfilov (@kotekjedi_ml) August 11, 2026

What the public logs contained

To demonstrate real-world damage, the team scraped 6,708 publicly shared AI agent transcripts—automated session logs that developers routinely post to GitHub and Hugging Face for collaboration or debugging. They decoded 315,320 reasoning blocks from those logs.

“Developers frequently share their session logs and encrypted thinking traces publicly online, entirely unaware of the sensitive data hidden within the encrypted blocks,” the paper notes. Most of those secrets never appeared in the visible AI output—they existed only inside the encrypted reasoning, invisible to anyone who hadn’t run the attack.

The vulnerability opens four attack vectors beyond simple credential theft: stealing proprietary reasoning patterns from AI companies to train competing models via distillation (when a smaller AI learns to mimic a bigger one by studying its outputs); extracting private data from shared logs; executing invisible prompt injection, where malicious instructions are hidden inside encrypted reasoning blocks that security monitoring tools never see; and jailbreaking powerful models through their less-guarded siblings.

Anthropic, OpenAI, and Google all deployed server-side mitigations after the team followed responsible disclosure procedures. As Decrypt previously reported, Anthropic has been a recurring focus for security researchers this year, especially as its latest models consume a lot more tokens in that process.

The patches are live. The 6,708 session transcripts with decoded reasoning blocks already scraped from the public web are not going anywhere.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Media & Culture

Not Ready For Prime Time: The Current State Of Legal Ethics And AI

19 minutes ago
Media & Culture

How Much Does New York Actually Recycle? The N.Y. Comptroller Says the State Doesn’t Really Know.

21 minutes ago
Cryptocurrency & Free Speech Finance

U.S. CPI inflation slows to 3.4% as expected, bitcoin (BTC) holds near $64,000

39 minutes ago
Cryptocurrency & Free Speech Finance

Hawaii Crypto ATM Ban to Take Effect on Oct. 1

41 minutes ago
Cryptocurrency & Free Speech Finance

The AI-Generated Pattern Hides You From Surveillance Cameras—Including Flock

48 minutes ago
Media & Culture

Government Regulations Are Keeping Drone Delivery Grounded

1 hour ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

How Much Does New York Actually Recycle? The N.Y. Comptroller Says the State Doesn’t Really Know.

21 minutes ago

U.S. CPI inflation slows to 3.4% as expected, bitcoin (BTC) holds near $64,000

39 minutes ago

Hawaii Crypto ATM Ban to Take Effect on Oct. 1

41 minutes ago

The AI-Generated Pattern Hides You From Surveillance Cameras—Including Flock

48 minutes ago
Latest Posts

How the unraveling of Jason Arday’s career and the UK’s censorship collided

1 hour ago

Government Regulations Are Keeping Drone Delivery Grounded

1 hour ago

Federal court should dismiss charges against independent journalists Georgia Fort, Don Lemon

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Not Ready For Prime Time: The Current State Of Legal Ethics And AI

19 minutes ago

How Much Does New York Actually Recycle? The N.Y. Comptroller Says the State Doesn’t Really Know.

21 minutes ago

U.S. CPI inflation slows to 3.4% as expected, bitcoin (BTC) holds near $64,000

39 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.