Cybersecurity Research

Researchers Show Encrypted AI 'Reasoning Traces' Can Be Exposed, Leaking Passwords and Personal Data

Embrace The Red · 17 Aug 2026
Key Takeaway Treat any exported AI chat logs or session files as potentially sensitive, and avoid posting them publicly or sharing them outside your organisation, since they may contain recoverable passwords and personal data even when encrypted.

Security researchers have published findings showing that encrypted 'reasoning traces', the hidden internal thinking process behind responses from AI chatbots like those from OpenAI and Anthropic, are not as protected as businesses might assume. These traces are sent back and forth during conversations in an encrypted, scrambled format, but the research shows this encrypted data can sometimes be replayed and decoded, even across different sessions, accounts, and AI models.

The technique works by taking an encrypted reasoning blob and feeding it to a separate, less secure AI model that can be tricked (or 'jailbroken') into revealing the original hidden content. This appears possible because AI providers may reuse the same encryption approach across many users and models. Researchers tested this at scale, decoding over 315,000 reasoning blocks scraped from publicly available repositories and recovering hundreds of exposed passwords, API keys, and personal information. A cybersecurity researcher independently reproduced the technique against a current OpenAI model and confirmed it could extract meaningful details from supposedly encrypted data.

This matters for small businesses because employees may unknowingly share files or logs containing these encrypted blobs, for example when troubleshooting with IT support or posting to public code repositories, without realising they contain recoverable sensitive information such as credentials.

AI security data leakage LLM vulnerabilities
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Embrace The Red. We link back to every original so you can read it yourself.