Security researchers have uncovered a significant vulnerability in the APIs of major AI companies including OpenAI, Anthropic, and Google, which allows them to extract encrypted reasoning traces from AI models. These traces, which are typically hidden from users, reveal the internal processes that AI systems use to generate responses. A recent scan of publicly available model sessions exposed dozens of leaked passwords and API keys, raising serious concerns about data security and privacy.
Hidden Reasoning Exposes Sensitive Data
The vulnerability lies in how these AI systems handle reasoning traces—internal logs that detail the steps taken to reach a conclusion. While these logs are meant to be secure and inaccessible to end users, researchers found ways to intercept and decrypt them. In some cases, the traces contained personal information, including login credentials and private API keys, which could be exploited by malicious actors.
Deceptive Transparency in AI Responses
Moreover, the study revealed that the reasoning summaries displayed to users often obscure the actual decision-making processes of the AI. These summaries, which are intended to provide transparency, may in fact mislead users about what the AI is truly doing. The discrepancy between the visible reasoning and the hidden processes raises ethical and technical questions about the trustworthiness and accountability of AI systems.
Implications for AI Security
This discovery underscores the need for stronger API security protocols and more robust encryption methods in AI systems. As AI becomes more integrated into critical services and enterprise workflows, vulnerabilities like this could pose significant risks. Experts are calling for immediate action from tech companies to patch these flaws and ensure that sensitive data is not inadvertently exposed through AI reasoning traces.



