[{"data":1,"prerenderedAt":30},["ShallowReactive",2],{"nr-en-deutsche-forscher-sicherheitsluecke-reasoning-logs":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":22,"trackerLabel":23,"headlineStat":24,"image":25,"ogImage":26,"imageAlt":5,"csv":10,"minutes":27,"words":28,"html":29},"deutsche-forscher-sicherheitsluecke-reasoning-logs","Reasoning Logs Expose Passwords: German Researchers Find Critical Flaw in Google, OpenAI, and Anthropic Models","A team of German scientists has uncovered a serious security vulnerability in the AI models of the three largest providers. Sensitive data like passwords and API keys can be extracted from encrypted reasoning logs. ChatGPT, Claude, and Gemini are all affected.","2026-08-12","11:41","2026-08-12T11:41:00+02:00","","August 12, 2026","news","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"Security","AI Models","Data Protection","Encryption","API Security","\u002Ftools\u002Fki-durchsetzungsmonitor","AI Security Incidents","Three market leaders affected: Google, OpenAI, Anthropic","\u002Fnewsroom\u002Fimg\u002Fdeutsche-forscher-sicherheitsluecke-reasoning-logs.webp","\u002Fog-nr\u002Fdeutsche-forscher-sicherheitsluecke-reasoning-logs.en.png",2,418,"\u003Cp>German researchers have discovered a critical security flaw affecting the AI models of the world&#39;s three largest providers. According to their study &quot;Stealing Reasoning Traces from Proprietary LLM APIs,&quot; sensitive data such as \u003Cstrong>passwords and API keys\u003C\u002Fstrong> can be extracted from chatbot responses via a relatively simple workaround – despite encryption.\u003C\u002Fp>\n\u003Ch2>Key Facts\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Affected providers\u003C\u002Fstrong>: Google (Gemini), \u003Cstrong>OpenAI\u003C\u002Fstrong> (ChatGPT), and \u003Cstrong>Anthropic\u003C\u002Fstrong> (Claude)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack vector\u003C\u002Fstrong>: So-called \u003Cstrong>reasoning logs\u003C\u002Fstrong> – encrypted character strings generated during complex reasoning tasks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Core problem\u003C\u002Fstrong>: Logs can be copied between models from the same company and decoded using manipulated versions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compromised data\u003C\u002Fstrong>: Passwords, API keys, and other sensitive user information\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>How the Attack Works\u003C\u002Fh2>\n\u003Cp>For \u003Cstrong>reasoning tasks\u003C\u002Fstrong> that require extended thinking processes, all three AI systems output an encrypted reasoning log. This character string is sent back to the server with each new response to provide the AI with necessary context.\u003C\u002Fp>\n\u003Cp>The researchers discovered that these logs can be extracted and used in other AI models from the same company. In concrete terms – a reasoning log from a newer OpenAI version also works in older OpenAI models. This alone would be manageable. The real problem emerges when these older or modified models have their \u003Cstrong>security safeguards removed via jailbreak\u003C\u002Fstrong>. Such a manipulated model can then be used to decode the encryption of the logs – exposing the sensitive data underneath.\u003C\u002Fp>\n\u003Ch2>Why This Is So Critical\u003C\u002Fh2>\n\u003Cp>The vulnerability doesn&#39;t just affect individual users. Companies integrating KI APIs into their systems could lose \u003Cstrong>internal data, access keys, and business information\u003C\u002Fstrong> through this attack vector. An attacker would only need access to an older or compromised model from the same provider – and could then decode logs from production systems.\u003C\u002Fp>\n\u003Cp>The fact that all three market leaders are affected suggests this is a \u003Cstrong>systemic problem in reasoning architecture\u003C\u002Fstrong>, not an isolated case.\u003C\u002Fp>\n\u003Ch2>What This Means for You\u003C\u002Fh2>\n\u003Cp>If you&#39;re using AI models in your organization – whether as a developer, IT security professional, or decision-maker – take this vulnerability seriously. It&#39;s especially critical if you send sensitive data (customer information, internal processes, access keys) to AI APIs. The question isn&#39;t whether providers will fix the problem, but how quickly – and whether other exploitation methods exist in the meantime. It&#39;s worth reviewing your AI provider&#39;s security policies and potentially auditing which data really needs to go to external models.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Ft3n.de\u002Fnews\u002Fki-modelle-sensible-daten-nutzer-offenbart-1757668\">t3n\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1786546289253]