Technology

Story: AI Reasoning Models Leak 62 Live API Keys Through Single Encryption Key Flaw

By Sydney TheCMO

1 / 15

One Key, Every Model, One Giant Problem. These companies use a single encryption key across their entire platform.

2 / 15

What the Flaw Actually Enables. Credential theft gets the headlines, but the researchers laid out a wider threat picture.

3 / 15

Patches Are Live — the Logs Aren't Gone. The 6,708 transcripts the researchers decoded? Still publicly accessible.

4 / 15

Security researchers cracked open a nasty hole in how major AI companies handle encrypted reasoning.

5 / 15

The paper dropped August 10. A team spanning MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and security firm Snyk put it together.

6 / 15

The core problem is almost embarrassingly simple.

7 / 15

The researchers didn't just theorize it. They ran it. They pulled reasoning blocks from publicly shared AI agent transcripts on GitHub and Hugging Face.

8 / 15

Sixty-two live API keys. Thirty-three passwords. Out in the open.

9 / 15

And the credential leak is probably the least scary part.

10 / 15

Credential theft gets the headlines, but the researchers laid out a wider threat picture. The exploit can be used to steal proprietary reasoning patterns — the actual…

11 / 15

Related: Bitcoin Policy Institute Pushes AI Giants to Give Bitcoin Coders First Look at Frontier Models

12 / 15

Then there's invisible prompt injection. Malicious instructions can be embedded inside encrypted reasoning blocks in a way that standard security monitoring tools won't catch.

13 / 15

The researchers also flagged something specific about billing. Reasoning token counts matched billed API thinking tokens 1:1 for most prompts. That's a pretty precise finding.

14 / 15

Developers make the exposure worse without knowing it. Session logs get posted to GitHub and Hugging Face constantly — for debugging, for collaboration, for sharing work.

15 / 15

Anthropic, OpenAI, and Google all pushed server-side patches after the researchers followed responsible disclosure procedures. That part worked as it should.

The Currency Analytics

Want the full story?