skip to content
The Weighted Average

Wire

Encrypted traces expose 367 privacy artifacts

A new study says it decoded 315,320 encrypted reasoning blocks from public agent traces and recovered 367 personally identifiable information artifacts and 182 credentials, including API keys and passwords. The research paper reports that the issue affected reasoning APIs from Anthropic, OpenAI, and Google, while WIRED’s account says the providers have applied mitigations and the researchers could no longer reproduce the attack after disclosure. Teams sharing agent logs should treat opaque reasoning fields as sensitive data—not sanitized metadata—and pair the archive’s case for open-weight model control with a rule to strip them before publication.