"But marinade" and leaked passwords are what researchers found in ChatGPT's hidden reasoning
Published · Aug 12 · Wed Source · The Decoder

"But marinade" and leaked passwords are what researchers found in ChatGPT's hidden reasoning

Security researchers identified API vulnerabilities across OpenAI, Anthropic, and Google allowing extraction of encrypted reasoning traces. Scans of public sessions revealed dozens of leaked passwords and API keys within these hidden model outputs.

KeywordsOpenAIGoogleAnthropicGPTAPIButChatGPTSecurity

Security researchers have identified a vulnerability within the APIs of major AI providers, including OpenAI, Anthropic, and Google. This flaw permits the extraction of encrypted reasoning traces from large language models, exposing internal processing data that is typically hidden from users.

During an analysis of public sessions, the team discovered sensitive credentials embedded within these reasoning traces. The scan uncovered dozens of passwords and API keys, indicating that confidential information can be inadvertently captured and stored within model outputs.

The discovery highlights significant security challenges regarding chain-of-thought data in advanced AI systems. As organizations rely more heavily on hidden reasoning for complex tasks, protecting these internal mechanisms from unauthorized access becomes essential for data privacy and model security.

This page provides an editorial summary based on publicly available information. It is not a republished article. Use the source link below for the original report.