Researchers Decoded 315,320 AI Reasoning Blocks and Found 182 Credentials, No Public Fix Followed
A replay attack against OpenAI, Anthropic, and Google APIs allowed researchers to extract plaintext from encrypted reasoning blocks, uncovering 182 credentials and 367 personally identifiable information artifacts across 6,708 publicly posted agent trajectories. All three providers acknowledged the findings and implemented mitigations that stopped the attack in later tests, but none has publicly announced an architectural fix, issued a CVE, or told enterprise customers which credentials to rotate. Decision-makers currently have no public confirmation that the underlying session-binding flaw has been resolved or guidance on scoping their own exposure.