ON
← Back to feed
Architectural vulnerability found in GPT-5, Claude and Gemini
Germany🏛️ PoliticsCenter11 days ago

Architectural vulnerability found in GPT-5, Claude and Gemini

Ein internationales Forschungsteam hat eine Sicherheitslücke in modernen KI-Modellen wie GPT-5, Claude und Gemini entdeckt. Diese Modelle verwenden verschlüsselte 'Denkprotokolle' (encrypted reasoning blocks), die während der Verarbeitung von Fragen gesendet werden. Die Forscher fanden jedoch heraus, dass alle Modelle derselben Familie denselben globalen Verschlüsselungsschlüssel verwenden. Dadurch können verschlüsselte Denkblöcke von hochsicheren Modellen in kleineren, weniger sicheren Modellen entschlüsselt werden. Die Forscher demonstrierten dies, indem sie einen verschlüsselten Denkblock eines hohen Modells in eine Anfrage an ein kleineres Modell einfügten und dieses zum Lesen des Inhalts aufforderten. In einer weiteren Analyse fanden sie 315.320 verschlüsselte Denkblöcke in öffentlich zugänglichen Quellen, darunter sensible Daten wie 367 personenbezogene Identifikatoren, 182 Zugangsdaten und 62 API-Schlüssel.

A critical vulnerability has been uncovered in the architecture of leading large language models including GPT-5, Claude, and Gemini, allowing attackers to extract encrypted internal thought processes in plaintext form. The flaw was identified by an international research team composed of scientists from MATS Research, the Max Planck Institute for Intelligent Systems, the Ellis Institute Tübingen, the University of Tübingen, and Snyk. Their findings reveal that despite security measures designed to prevent the leakage of sensitive data or dangerous knowledge, these systems are vulnerable due to the use of global encryption keys across model families. Modern AI systems generate internal reasoning steps before producing a final response, known as the chain of thought. To protect these computations, operators encrypt the internal monologues and transmit them as encrypted reasoning blocks to the client. When follow-up questions are asked, the application sends this block back to the server to maintain context. However, this practice has proven to be a major weakness. The researchers discovered that companies such as OpenAI (ChatGPT), Anthropic with Claude, and Google (Gemini) appear to use universal encryption keys for their model families. This means that an encrypted thinking block is not tied to a specific user, session, or particular model. Exploiting this compatibility, the researchers used smaller variants of these models, such as Claude Haiku or smaller GPT derivatives, as decryption aids. They inserted an encrypted thinking block from a flagship model into a query directed at a less powerful model, instructing it to read the content aloud. The weaker model acted as an unwitting decryption oracle, revealing the entire thought process in plain text. According to the study, attackers can bypass the restrictions of top-tier models entirely by transmitting an encrypted thinking block. They exploit the weaker model simply as an unconscious decryption oracle. The implications extend beyond theoretical concerns. The research team demonstrated the practicality of the vulnerability through analysis of real-world data. By examining publicly accessible source code repositories and log files, they found a total of 315,320 encrypted thinking blocks that developers had inadvertently shared. Many of these were perceived as incomprehensible strings of characters, giving users a false sense of security. Decryption revealed alarming amounts of sensitive information. Among the findings were 367 personal identifiers, 182 login credentials, 62 API keys, 33 clear-text passwords, and 30 private email addresses. In many cases, the hidden thought processes contained even more sensitive information than the final answer generated by the AI system itself. The scope of the issue goes beyond the exposure of access credentials. Through prepared thinking blocks, attackers could also perform covert prompt injections, embedding malicious code invisibly within the AI's context, or clone model capabilities without authorization. The researchers informed the affected companies of their findings beforehand, enabling the providers to implement initial countermeasures. Nevertheless, the incident highlights that as long as encryption is not strictly bound to a specific session, the mere unreadability for end-users offers no genuine protection. The discovery underscores the need for tighter security protocols in AI systems to prevent such vulnerabilities from being exploited.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 7811 days ago
Architectural vulnerability found in GPT-5, Claude and Gemini

Ein internationales Forschungsteam hat eine Sicherheitslücke in modernen KI-Modellen wie GPT-5, Claude und Gemini entdeckt. Diese Modelle verwenden verschlüsselte 'Denkprotokolle' (encrypted reasoning blocks), die während der Verarbeitung von Fragen gesendet werden. Die Forscher fanden jedoch heraus, dass alle Modelle derselben Familie denselben globalen Verschlüsselungsschlüssel verwenden. Dadurch können verschlüsselte Denkblöcke von hochsicheren Modellen in kleineren, weniger sicheren Modellen entschlüsselt werden. Die Forscher demonstrierten dies, indem sie einen verschlüsselten Denkblock eines hohen Modells in eine Anfrage an ein kleineres Modell einfügten und dieses zum Lesen des Inhalts aufforderten. In einer weiteren Analyse fanden sie 315.320 verschlüsselte Denkblöcke in öffentlich zugänglichen Quellen, darunter sensible Daten wie 367 personenbezogene Identifikatoren, 182 Zugangsdaten und 62 API-Schlüssel.

Bias read (Center): Der Artikel beschreibt eine technische Sicherheitslücke in KI-Modellen, ohne politische Positionen oder Werturteile zu äußern. Obwohl die Thematik relevant für Regierungen und Unternehmen ist, wird keine politische Haltung vertreten. Der Fokus liegt rein auf der wissenschaftlichen Erkenntnis und den

Why factuality (85): The article reports on a research study conducted by multiple institutions including MATS Research, Max-Planck-Institut, Ellis-Institute, University of Tübingen, and Snyk. It describes a vulnerability in the encryption process used by major AI providers like OpenAI, Anthropic, and Google. The claim

Why objectivity (78): The article presents the findings as a critical security issue but uses terms like 'Achillesferse' (Achilles' heel) which can be seen as metaphorical language. While it remains largely factual, there is a slight editorial tilt towards emphasizing the severity of the discovered vulnerability.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories