FAIL · AI INCIDENT TRACKER

wire / 2026-08-11-9ec3

Flaw in Major AI APIs Exposes Hidden Reasoning and Sensitive Data

August 11, 2026 · DEU INCIDENT RIGHTSREPUTATIONAL

A weaker model can be pointed at OpenAI, Anthropic, and Google's encrypted reasoning blocks and pull out the plaintext, plus API keys and passwords lifted from public logs. Encryption remains a strong word.

The facts

Researchers discovered a vulnerability in the APIs of OpenAI, Anthropic, and Google that allowed weaker AI models to extract hidden reasoning steps, API keys, and passwords from encrypted reasoning blocks. Thousands of private artifacts were exposed from public logs, revealing significant privacy and security risks due to flawed AI system design.