2026-08-13-Thu

From Issue 12 (2026-08-13) · 13 stories in this issue

❯ Researchers Use Same-Vendor Weaker Models to Decode Stronger Models’ Encrypted Chain-of-Thought, Netting 182 Credentials

BREACHAccording to Wired, researchers found that feeding a frontier model’s encrypted reasoning traces to a weaker, less-guarded model from the same vendor causes the latter to decode the content into plaintext output verbatim. The process requires no jailbreaking of the strong model, no breaking of the encryption itself, and no access to keys — only standard, unprivileged API permissions.

STRUCTUREThe problem lies in the design. To protect intellectual property, vendors no longer store chain-of-thought on the server side; instead, it is encrypted and returned to the client, which sends it back in subsequent requests. These encrypted blocks are fully interoperable across sessions, users, and models within the same vendor’s ecosystem — and that interoperability is itself the key. The paper states that all three systems — Claude, GPT, and Gemini — are affected.

HARVESTThe researchers recovered 315,000 reasoning blocks from public code repositories, extracting 367 pieces of personally identifiable information and 182 credentials — data that any API caller could already have retrieved. In other words, the leak is not a theoretical risk; it is a fait accompli already sitting in public repositories.

CLEANUPWhat needs to be re-audited is the engineering habit of writing reasoning traces into logs or version-control repositories. Developers previously assumed this ciphertext was unreadable and therefore committed and stored it casually; that premise no longer holds. On the vendor side, what needs to change is the scope binding of encrypted blocks — without binding to a session or a model, it amounts to no encryption at all.

▪ SIGNALThe encryption wasn’t broken — what was broken is the default assumption that models from the same vendor can read each other.