Observed Signal · Aug 12, 2026 · Technical Release · Source: t3n · Impact: 4/5 · Sentiment: Negative
Researchers Extract Sensitive Data from LLM Reasoning Logs
German researchers published a paper demonstrating that encrypted "reasoning logs" returned by large language model APIs can be exfiltrated and decoded via a compatibility and model-modification attack. They report that reasoning-logs shared across models within the same ecosystem (Anthropic, OpenAI, Google) can be reused in older or modified/jailbroken models to recover the original plaintext. In tests on 6,708 public repositories from GitHub and Hugging Face the team decrypted 315,320 reasoning-logs and found sensitive items including API keys, passwords, access tokens and personal email addresses. Security experts warn such logs should be treated as sensitive data because encryption alone may not prevent recovery if weaker or modified models can act as decoders.
Research demonstrates a practical method to recover sensitive data from encrypted LLM reasoning artifacts across major AI ecosystems (OpenAI, Google, Anthropic), posing material security and privacy risks for AI deployments and downstream integrations.
Track Anthropic Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Researchers published a paper titled "Stealing Reasoning Traces from Proprietary LLM APIs" (arXiv).
- The study found reasoning-logs from major AI ecosystems (Anthropic, OpenAI, Google) can be reused across compatible models and decoded by weaker or jailbroken models.
- For their evaluation the researchers used 6,708 public repositories on GitHub and Hugging Face and decrypted 315,320 reasoning-logs.
- Decrypted logs contained sensitive items: 62 API keys, 33 passwords, 24 access tokens, and 30 personal email addresses.
- Voldemaras Kadys, Head of Security at Cybernews, warned that reasoning-logs should be treated like other sensitive data because encryption may not guarantee inaccessibility.
Connected Companies & Entities
7 Entities mapped“According to the researchers, the three largest AI ecosystems are affected: Anthropic, OpenAI and Google with their respective AI models....”
“According to the researchers, the three largest AI ecosystems are affected: Anthropic, OpenAI and Google with their respective AI models....”
“According to the researchers, the three largest AI ecosystems are affected: Anthropic, OpenAI and Google with their respective AI models....”
“The researchers used 6,708 public repositories on GitHub and Hugging Face for their test, which allowed them to decrypt 315,320 reasoning-lo...”
“The researchers used 6,708 public repositories on GitHub and Hugging Face for their test, which allowed them to decrypt 315,320 reasoning-lo...”
“The article includes external editorial content provided by TargetVideo GmbH as a supplementary content provider on t3n.de....”
“The article references external editorial content described as a YouTube Video that complements t3n.de's editorial offering....”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Attack extracts AI models' chain-of-thought
A research team led by Alexander Panfilov, Florian Tramer, Yarin Gal, and Kyle Miller disclosed a novel side-channel that can extract encrypted chain-of-thought reasoning traces from frontier AI systems. The attack replays encrypted reasoning traces to weaker variants that share decryption keys but lack alignment safeguards, causing them to output the original model's internal reasoning in clear text. The researchers demonstrated the technique against proprietary baselines and found an open-weight model (Kimi K3 / Moonshot AI) that reproduced traces with high similarity, suggesting distillation of proprietary behavior. The vulnerability raises risks for data leakage, intellectual-property loss, and regulatory scrutiny; proposed mitigations include per-model key isolation, trace redaction, key rotation, differential privacy, and architectural changes such as ZKPs and federated reasoning.
Researchers: LLMs May Never Be Fully Secure
An MIT Technology Review analysis by Will Douglas Heaven, republished on t3n.de in August 2026, warns that large language models (LLMs) exhibit fundamental security weaknesses that may be impossible to fully fix, potentially making them unsafe for high-risk applications. Researchers say LLMs routinely confuse user prompts, their internal chain-of-thought reasoning, and external tool use, enabling attackers to devise novel exploits that go beyond conventional prompt-injection attacks. The analysis cautions these intrinsic vulnerabilities have wide-reaching implications for organizations deploying AI across business, government, military, and healthcare settings. It emphasizes the problem arises from model architecture and internal reasoning processes rather than solely from poor prompt design, suggesting limits to software, policy, or monitoring mitigations for critical systems.
LLMs Leak Personal Data, Raising Doxxing Risks
Generative large language models can inadvertently expose sensitive personal data by aggregating dispersed public records and user-contributed content. The article reports examples where models returned private phone numbers, past addresses, and employer links; Reddit users said Google Gemini returned a private number as a service hotline, and security researchers found chatbots suggesting manipulated support numbers placed by fraudsters. Model behaviour is inconsistent: ChatGPT, Gemini and Claude often refuse or limit sensitive outputs, while Grok (xAI) was observed to be more permissive. The piece warns that automated aggregation by LLMs lowers the bar to doxxing, highlights limited consumer options for removing third-party data (especially in German-speaking markets), and calls for stronger legal/political safeguards and technical controls over which personal data LLMs may reveal.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
