Dozens of passwords and API keys found in ChatGPT's hidden reasoning
Security researchers uncovered dozens of passwords and API keys while scanning public sessions of ChatGPT. This vulnerability highlights that the reasoning summaries presented to users often obscure the underlying actions of the models, as noted by the researchers. OpenAI, Anthropic, and Google were involved in this discovery, emphasizing the collaborative nature of AI security research. This incident raises concerns for developers relying on ChatGPT for sensitive applications, as it reveals potential risks in data handling and model transparency. The findings align with ongoing discussions about AI security and transparency, following previous reports on OpenAI’s testing of ads in ChatGPT to support free access, which could further complicate user trust. For more details, see The Decoder.
By Callan Zhang · Aug 11, 2026 · Editorial standards →
Summarised from the primary source with AI assistance under human editorial oversight. Turing Wire is not a primary source — read the original for the authoritative account.
Source: The Decoder