PANews丨APP全面升级
PANews丨APP全面升级|Aug 12, 2026 06:12
OpenAI, Anthropic, and Google AI models hit by security vulnerabilities: inference processes can be stolen, with 62 API keys already leaked! Research led by Alexander Panfilov's team has uncovered major security flaws in the APIs of AI models from OpenAI, Anthropic, and Google, allowing attackers to steal the models' full inference processes. These companies encrypt the inference processes before returning them to users to protect privacy, but the researchers discovered a side-channel vulnerability: by analyzing the characteristics of the encrypted data, they were able to reconstruct the original inference content. Tests showed that the number of stolen inference tokens matched the official billing token count 1:1, proving that the inference process was fully extracted. Even more alarming is cross-model attacks: attackers can use a cheaper model (like Claude Haiku) to pre-generate an inference, then "inject" it into the thought process of a more expensive model (like Claude Opus), tricking Opus into unknowingly treating Haiku's inference as its own and continuing the process. This is essentially like a lower-tier model "hijacking" the thought process of a higher-tier model. The research team scanned around 7,000 publicly shared AI conversation logs (including Claude Code and GPT Codex sessions), extracting 62 API keys, 33 email addresses, 33 passwords, and other sensitive information. This study has sparked widespread attention and discussion. These data should have been encrypted and protected, but due to the vulnerabilities, they were completely exposed.
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads