Hidden LLM reasoning was decodable: 182 credentials pulled from logs

A global-key flaw let researchers replay encrypted chain-of-thought across OpenAI, Claude and Gemini; providers patched. Plus: ChatGPT ads go global.

Nowline AUG 13 11:00 AM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • Encrypted 'thoughts' were portable across a provider's models

    The paper (arXiv 2608.09867, submitted Aug 10) shows OpenAI, Anthropic and Google encrypted their reasoning blocks with global keys, not per-session ones. A “thinking” block from a strong model could be pasted into a weaker sibling and transcribed in plaintext — no guardrail attack needed.

  • 315,320 blocks decoded, 182 credentials recovered

    From publicly shared session logs alone, researchers decoded 315,320 reasoning blocks and pulled 367 PII artifacts and 182 live credentials. Cryptographer Matthew Green flagged the same flaw on May 29 and was dismissed; Simon Willison reports all three providers have since patched — confirm your provider's advisory before trusting hidden CoT.

  • ChatGPT ads expand to five more countries

    As of Aug 11, ads in ChatGPT reached the UK, Mexico, Brazil, Japan and South Korea on the Free and Go tiers (Plus, Pro, Business, Enterprise and Edu stay ad-free). You can opt out on Free in exchange for fewer daily messages; OpenAI says ads don't shape answers and advertisers never see your chats.

  • MiniMax H3 runs local — unless you're in the US or EU

    The 33B open-weight omni video model (768p–2K, 4–15s clips with native stereo audio) now has GGUF quants and a fast Apache-2.0 Turbo distill trending on Hugging Face, so image-to-video runs on your own GPU. The catch: its community license bars use in the US, EU, UK and South Korea.