← Back to feed
AI SecurityEmerging1 sourceAug 11, 2026 · 15:35via Cyber Security News

OpenAI, Anthropic, and Google LLM APIs vulnerability Exposes Hidden Reasoning Traces

Brief

A significant architectural flaw in how major AI providers, including OpenAI, Anthropic, and Google, protect the internal “chain-of-thought” reasoning generated by their flagship large language models (LLMs).

The research reveals that encrypted reasoning envelopes returned by provider APIs can be replayed into weaker, less-guarded sibling models to extract private reasoning traces in plain text.

Detailed by a collaborative research team from the ELLIS Institute Tübingen, the Max Planck Institute, MATS Research, and Snyk, the attack affects the Claude, GPT, and Gemini model ecosystems and requires only standard, unprivileged API access.

APIs Flaw Exposes Hidden Reasoning Traces

Modern reasoning architectures such as GPT-5. 6, Claude Opus 4. 8, and Gemini 3 construct hidden chain-of-thought processing traces prior to returning a final response.

Read more on Cyber Security News