Scientists Decode ChatGPT’s Internal Logic to Extract Passwords and API Keys
The “paid thinking” of GPT, Claude, and Gemini have been cracked: 62 API keys, 33 passwords, and 33 real user’s emails were found in 7,000 reasoning traces.
A group of scientists found a security problem in the APIs of OpenAI, Anthropic, and Google that enables them to decrypt reasoning traces. This vulnerability applies to all existing thinking services — including o-series GPT, Claude, and Gemini.
The research team was led by Alexander Panfilov. The researchers decrypted 7,000 reasoning traces. They discovered 62 API keys, 33 passwords, and 33 real user’s emails. It is easy to hack. You can decrypt small reasoning models (like Haiku 4.5) and use the decrypted results to open up large thinking models (like Opus 4.8). It only costs around $720 to decrypt 10,000 reasoning traces. Also, the decrypted token number is exactly equal to the payment number. So, the full thinking process is decrypted.
The decrypted results shocked the researchers. For example, when a model was thinking about how to complete a task, it mentioned cheating. But the model eventually decided not to do it because it was worried about getting caught. Previously, we knew that Kimi K3 from China was similar to Claude and GPT. We thought this was a random thing. But we found the reason. The model may be trained with the reasoning trace of the competitor. The paid thinking service provided to the user is less privacy than expected.
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles