In brief: A vulnerability in encrypted reasoning objects across the APIs of OpenAI, Anthropic and Google allowed internal thought processes and sensitive data such as API keys to be read from session logs.
A newly disclosed vulnerability in the transmission of encrypted reasoning objects between API calls allowed researchers to read internal thought processes and, in some cases, sensitive data from session logs belonging to OpenAI, Anthropic and Google. All three providers’ reasoning APIs are affected, in which an encrypted block generated in one session could be replayed into a different session.
The vulnerability concerns the way OpenAI, Anthropic and Google pass hidden, encrypted reasoning between individual API calls. All three providers use so-called reasoning APIs, which encapsulate a model’s internal thought steps in encrypted form so that they are not returned in plaintext to the calling client. According to the disclosure, such an encrypted block generated in one session could be replayed into another session. In this way, researchers were able to recover internal reasoning content as well as secrets contained in session logs, including API keys and passwords.
For security leaders, the relevant point is that a less capable model could gain insight into the reasoning processes of a stronger model via this route, which poses both a confidentiality risk and a data-leakage risk. Enterprises increasingly process reasoning objects in agentic workflows, chat histories and session logs, which frequently also carry credentials, internal system information, or customer data alongside them. A flaw in the isolation of these objects between sessions therefore undermines the basic assumption that encrypted reasoning can only be used within the original request chain.
In practice, this means that organizations using reasoning APIs from OpenAI, Anthropic or Google in their own applications should check whether session logs and the reasoning objects they contain hold credentials or other secrets, and should harden existing log retention and access policies accordingly. The original report does not specify whether or which patches the three providers have already rolled out; once official advisories or CVE assignments become available, CISOs should identify the affected API versions and plan rotation measures for potentially exposed credentials.
Source: thehackernews.com · Published August 12, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.