The AI Read
← Timeline
Aug 16 2026

A paper shows encrypted reasoning traces from Anthropic, OpenAI and Google APIs are interchangeable and decodable across sessions and models, recovering 367 personal-information items and 182 live credentials from 315,320 scraped blocks

SAFETY
Original reporting

No source was cited for this one in the issue that logged it. The link above searches for it instead of guessing at a URL.

Injecting a capable model's encrypted trace into a weaker, less-guarded sibling from the same provider decodes the hidden reasoning verbatim, defeating anti-distillation protections and opening an invisible indirect-prompt-injection channel no scanner reads.

Named in this event

AnthropicOpenAIGoogle

Open calls that touch this
Issues that mention Anthropic, OpenAI, Google
Around the same time