Researchers have discovered that publicly shared LLM API logs may still contain sensitive customer data, such as API keys and passwords, hidden within encrypted reasoning blocks. This vulnerability, detailed in an August 2026 preprint, involves a replay attack where encrypted blocks are fed to a weaker model to extract hidden content. While providers like Anthropic, OpenAI, and Google have implemented mitigations against new attacks, it remains unconfirmed if they have retroactively invalidated older, already-published cryptographic envelopes, leaving past data potentially exposed. The researchers recovered 704 distinct sensitive artifacts from public agent trajectories, including credentials and personally identifiable information, some of which were not visible in the chat history. AI
IMPACT Highlights a potential data leakage vector that could impact user trust and require retroactive security measures from LLM providers.
RANK_REASON The cluster details a research paper reporting on a security vulnerability in LLM API logs. [lever_c_demoted from research: ic=1 ai=1.0]
Read on dev.to — Anthropic tag →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →