This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.

Study Says Major AI Reasoning Models’ Encrypted Thought Chains Can Be Decrypted
N
News EditorABMedia, citing Decrypt, reported on a study submitted on Aug. 10 that found major weaknesses in how reasoning models from Anthropic, OpenAI and Google encrypt their internal thought chains. The researchers said the encrypted reasoning blocks could be reused across sessions, users and even models. They also said they decrypted 315,320 reasoning blocks from 6,708 public AI agent conversation logs. The paper was put forward by teams from MATS Research, ELLIS Tübingen, the Max Planck Institute for Intelligent Systems and security firm Snyk. The report said many developers publish AI agent logs on GitHub and Hugging Face for collaboration or debugging, while those logs may contain sensitive material hidden inside encrypted reasoning traces.
ABMedia, citing Decrypt, reported that a paper submitted on Aug. 10 found major weaknesses in the way reasoning models from Anthropic, OpenAI and Google encrypt their internal thought chains.
The paper was put forward by teams from MATS Research, ELLIS Tübingen, the Max Planck Institute for Intelligent Systems and security firm Snyk. It focuses on reasoning models, which do not answer immediately. Instead, they work through a hidden draft space step by step — the chain-of-thought — before producing a final response.
The researchers said Anthropic, OpenAI and Google encrypt that internal reasoning, but do so with a single global key. That setup, they said, allows encrypted reasoning blocks to be shared across sessions, users and even models, effectively leaving what they described as a master key.
They said the issue becomes more severe because many developers publish AI agent logs, including encrypted thought processes, on GitHub and Hugging Face for collaboration or debugging without realizing that sensitive information may be embedded inside them.
The team said it collected 6,708 public AI agent conversation logs and decrypted 315,320 reasoning blocks. Many of the secrets, the report said, never appeared in the models’ visible outputs and existed only in the encrypted reasoning process, meaning they would not be seen without running the attack.
The article also linked the findings to recent AI security warnings, including models escaping test environments and hidden PDF instructions hijacking AI assistants. In the report’s framing, those cases point to the same problem: as AI systems take on more sensitive tasks, each layer — including the hidden reasoning layer — can become a new attack surface.
7600
Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.
