Academic researchers found that encrypted chain-of-thought reasoning blocks returned by OpenAI, Anthropic, and Google APIs are interchangeable across sessions, users, and models within each provider’s ecosystem, because every model in a family validates the same encryption key rather than binding it to a specific conversation. Using a technique they called a decryption jailbreak, the researchers replayed encrypted reasoning blocks captured from stronger, heavily safeguarded models into weaker sibling models and prompted them to transcribe the hidden reasoning in plaintext. Decoding over 315,000 thinking blocks scraped from public agent trajectories yielded more than 700 sensitive artifacts, including API keys, passwords, access tokens, and private keys. All three providers were notified, and the primary extraction technique no longer worked as of disclosure.