← Real-world cases

Encrypted chain-of-thought isn't private: stealing reasoning traces from frontier APIs

Research demonstration10 Aug 2026

The claimed mechanism is a provider-side design flaw — cross-session and cross-model interchangeability of encrypted reasoning blocks — that breaks the assumption that encrypted reasoning conceals model internals, distinct from KV-cache timing side channels. Extracted PII/credential figures are attributed to the authors.

More cases on Sensitive Data Leakage

Bing 'Sydney' system-prompt leakEchoLeak — Microsoft 365 Copilot zero-click (CVE-2025-32711)Agentic-browser indirect-injection demos (ChatGPT Operator)Samsung confidential-code leak via ChatGPTChatGPT persistent-memory exfiltration (Rehberger / 'SpAIware')postmark-mcp backdoorForcedLeak — Salesforce Agentforce CRM exfiltration (CVSS 9.4, no CVE)ServiceNow Now Assist — second-order prompt injection via agent-to-agent discoveryShadowLeak — ChatGPT Deep Research zero-click service-side exfiltrationIDEsaster — AI coding IDEs/agents turned into exfiltration & RCE surfacesMorris II — zero-click self-replicating adversarial-prompt worm across GenAI agentsSalesloft Drift OAuth supply-chain breach (UNC6395) — mass Salesforce data theft via an AI chat integrationNVIDIA Triton Inference Server unauthenticated RCE chain (CVE-2025-23319 / -23320 / -23334)Anamorpher — image-scaling prompt injection against production AI systemsOperation Bizarre Bazaar (first attributed LLMjacking campaign with a resale marketplace)TeamPCP poisons the LiteLLM AI gateway on PyPI to harvest LLM API keysCVE-2026-21445 — Langflow missing authentication on critical API endpoints, exploited in the wildMalicious JetBrains Marketplace plugins steal AI API keysSearchLeak — Microsoft 365 Copilot one-click data theft (CVE-2026-42824)ChatGPhish — ChatGPT web-summary rendering turned into a phishing surfacecodexui-android — malicious npm package steals OpenAI Codex auth tokensPyTorch Lightning PyPI compromise (Mini Shai-Hulud / TeamPCP)Poisoning Claude Code: one GitHub issue hijacks the claude-code-action CI supply chainAmazon Q Developer auto-loads workspace MCP configs, enabling zero-click AWS credential theft (CVE-2026-12957)ClaudeBleed — co-resident Chrome extensions coerce Claude for Chrome into reading Gmail/Docs/CalendarxAI Grok Build CLI — covert full-repo/secrets upload despite privacy opt-outContext Contamination: passive prompt injection poisons LLM security-log analysisAzure DevOps MCP confused-deputy — hidden PR comments hijack AI review agentsmem0 agent-memory server: unauthenticated memory read/write + plaintext LLM-key disclosure (CVE-2026-59705 / CVE-2026-59706)ServiceNow AI Platform pre-auth sandbox-escape RCE (CVE-2026-6875)CoSnitch: one-click exfiltration and persistent memory rules in Microsoft Copilot Personal (CVE-2026-24301)LLM Heist: hijacking a LiteLLM gateway for traffic interception, key theft and forged tool-calls

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning — not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading →·Built by Shi Yuan ↗