DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

OpenAI, Anthropic, Google APIs Let Weaker Models Steal Reasoning

Forensic Summary

Researchers disclosed a cross-session, cross-user flaw in the reasoning APIs of OpenAI, Anthropic, and Google, where encrypted reasoning blocks could be replayed by weaker models to expose hidden internal reasoning, private credentials, and harmful content. Across nearly 6,700 public agent trajectories, the team recovered 704 privacy artifacts including API keys, passwords, and private keys. All three providers have since deployed mitigations that stopped the demonstrated attacks, but the disclosure highlights systemic risks in how stateless API reasoning state is shared and published.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/openai-anthropic-google-apis-let-weaker-models-steal-reasoning/

Top comments (0)