• Sources: arXiv 2608.09867, author interview
  • Summary: The paper reports that the encrypted reasoning blocks returned by Anthropic, OpenAI, and Google are not bound to the request that produced them. The paper scopes the interchangeability to within one provider's ecosystem, where the same block can be replayed across sessions, across users, and across models, and it does not claim replay across providers. The authors scraped 315,320 reasoning blocks from public repositories and recovered 367 PII artifacts and 182 credentials from them. The source is a version 1 preprint submitted 2026-08-10 and it is not peer reviewed. The paper states the authors followed responsible disclosure and proposes cryptographic and system-level mitigations. No provider statement was located this run.
  • Why it matters: Any session log containing encrypted reasoning blocks is a credential and PII disclosure risk, and any public agent rollout carrying them is an injection vector.
  • Follow-up: Track provider responses and whether reasoning blocks gain per-session binding.

send feedback on this story