Flaw in Major AI Providers' APIs Exposed Hidden Reasoning Data, Including Secrets
Security researchers have disclosed a vulnerability affecting how OpenAI, Anthropic, and Google handle hidden AI 'reasoning' data passed between API calls. This reasoning data is normally encrypted and not meant to be readable outside the original session, but researchers found that a reasoning block created in one session could be replayed into another session and, in testing, weaker AI models were able to decode reasoning content from more advanced models.
More concerning, the researchers found that session logs containing this reasoning data sometimes included sensitive secrets such as API keys and passwords. This means that a flaw intended to only affect internal AI processing steps could potentially expose real, exploitable business credentials if logs or reasoning objects were accessed by unauthorised parties.
While the affected companies have been building AI services used by countless businesses worldwide, this incident is a reminder that even major AI providers can have security gaps in how they protect data behind the scenes. Businesses relying on third-party AI APIs should stay alert for vendor security advisories and patches related to this issue.