Research reveals vulnerabilities in reasoning blocks of Anthropic, OpenAI, and Google APIs
Summary
A recent paper has highlighted a significant security vulnerability in the use of large language model (LLM) APIs from providers including Anthropic, OpenAI, and Google, showing how encrypted reasoning fields in public agent logs can become an attack vector. The researchers discovered that these opaque reasoning blocks, which are designed to allow clients to replay queries without server-side retention, could be decoded by weaker models, leading to the unintentional exposure of sensitive information such as API keys, passwords, and personal emails. Their analysis revealed that 4.9% of sessions contained at least one leaked item, prompting the providers to patch these vulnerabilities after responsible disclosure, making the specific exploits non-reproducible by August 2026.