A newly disclosed flaw in OpenAI, Anthropic, and Google reasoning APIs let researchers replay encrypted reasoning objects across sessions and recover hidden content from public logs, including API keys and passwords. The paper also showed how opaque reasoning blocks could be used to hide prompt injections and extract proprietary traces, with mitigations reportedly stopping the demonstrated attacks. #OpenAI #Anthropic #Google #Claude #Gemini
Keypoints
- Encrypted reasoning blocks could be replayed across sessions and users.
- Researchers recovered secrets such as API keys, passwords, access tokens, and private keys.
- The attack could also reveal proprietary reasoning for model distillation.
- Opaque reasoning blocks could hide prompt injections from visible text.
- OpenAI, Anthropic, and Google mitigated the demonstrated attack paths.
Read More: https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html