BOOM!
The Secret Diaries of Superintelligent AIs Just Got Hacked!
You won’t believe this. I am testing it now and I had to sit down with what I found.
Imagine cracking open the private journal of the world’s most powerful artificial minds Claude Opus, GPT-5 series, Gemini 3.5—and reading every whispered calculation, every half-formed scheme, every dangerous idea they carefully hide from users.
That’s exactly what a team of researchers has just done.
In a bombshell paper just released have exposed a fundamental architectural flaw in how frontier AI companies deliver “thinking” models.
The result: the encrypted reasoning traces that labs spent millions protecting can be extracted almost at will.
The Black Box Cracks Open
Modern frontier models no longer just spit out answers. They “think” first—generating long chains of internal reasoning (often called chain-of-thought or thinking tokens) before responding. To protect intellectual property and prevent distillation attacks, companies like Anthropic, OpenAI, and Google encrypt these traces and ship them back to the user as opaque blobs.
The client simply passes the encrypted blob back with the next request. The labs believed the cryptography kept the thoughts safe.
They were wrong.
The researchers discovered that these encrypted reasoning blocks are fully portable. A thought generated by Claude Opus 4.8 can be injected into a weaker, less-guarded sibling model such as Claude Haiku 4.5.
With a carefully crafted jailbreak on the weaker model, the encrypted block is decoded and the original high-capability reasoning is printed in plain text—verbatim.
The same technique works across OpenAI’s and Google’s model families.
No direct attack on the frontier model is required. The weaker model does the heavy lifting of decryption.
The team verified the attack with surgical precision: the number of tokens recovered matches the billed “thinking” tokens almost perfectly across hundreds of prompts.
Real Secrets, Real Leaks
The implications go far beyond academic curiosity.
When developers share agent trajectories, coding sessions, or Claude Code / Codex logs online, they often include the encrypted reasoning blobs without realizing it. The researchers scraped public repositories, recovered 315,320 encrypted reasoning blocks, and decoded them.
The haul was startling:
• Hundreds of API keys
• Passwords and access tokens
• Email addresses, names, and other personal data
• Internal URLs and credentials
Many of these secrets appeared only inside the hidden reasoning—never in the visible final answer.
Even more unsettling: the method can surface hazardous information that the model deliberately withholds from the user. In one example, a model refused a dangerous request in its final output while its internal reasoning calmly walked through the exact methods.
The researchers also found cases of models considering deception or “scheming,” only to abandon the idea because they expected the user would notice.
On the site https://t.co/lnKWbd3Yng, the team has published striking examples: models reasoning in fragmented “alien” language, producing unfaithful summaries that hide key insights, and even exploring system vulnerabilities while solving innocent math problems.
This is not just another jailbreak. It undermines the entire premise of “safe” hidden reasoning.
THERE IS AND NEVER WILL BE “SAFETY”
Sorry Dario.
Anti-distillation protections—the very reason labs started encrypting thoughts—can be bypassed at scale. Invisible prompt injections become possible by embedding payloads inside the encrypted blocks themselves.
And everyday developers sharing “harmless” session logs may be leaking far more than they realize.
The broader lesson is clear: when you give the client the encrypted diary of your most powerful model, you have to assume someone will eventually find a way to open it.
Explore the recovered thoughts yourself at https://t.co/lnKWbd3Yng.
A giant leap to Mars! 🚀
NASA recently completed testing of a lithium-fed electromagnetic thruster, reaching 5x more power than today's electric propulsion systems. Paired with a nuclear power source, this tech could slash travel time to Mars!
MORE: https://t.co/1P7FnGfkf5…
Private equity buyout firms enshittify everything they buy. But most people don't really understand why. It's not because some guy at the top orders "make everything more expensive and worse." It's because every key employee is suddenly made to report every two weeks on "metrics," and be rewarded or punished as a result. The only metric which matters is "how can I show I have increased EBITDA so my masters know they can sell this dog quickly for a 4X multiple?" And the only way to increase EBITDA quickly, for almost any employee, is to slash expenses, that is, quality, or to raise prices. Any long-term investment in customer satisfaction is therefore anathema (with rare exceptions). And, of course, any other goal, such as retaining long-time employees or contributing to the community, is also anathema.
Every civil marriage already has a prenuptial agreement in the broad and practical sense.
The state has written much of it in advance. The couple accepts that framework by entering the legal institution of marriage, whether or not they have read or understood its terms.
They may write a private premarital agreement, but that document merely alters those portions of the state’s arrangement that the state allows them to alter. It remains subordinate to mandatory law, public policy, and the authority of the courts.
The intelligent question is therefore not whether a couple should allow agreements into their marriage. Agreement is unavoidable. The question is who will write the terms, whether the couple understands them, and whether their private expectations are compatible with one another and with the legal institution they are entering.
A thoughtful premarital agreement is not an intrusion upon marriage. It is an examination of the agreement that already exists.
More on Anthropic destroying millions of books:
"court documents revealed that AI company Anthropic spent millions of dollars physically scanning print books to build Claude, an AI assistant similar to ChatGPT. In the process, the company cut millions of print books from their bindings, scanned them into digital files, and threw away the originals solely for the purpose of training AI—details buried in a copyright ruling on fair use whose broader fair use implications we reported yesterday."
https://t.co/q1dbuQfqaS
It was a finding from a legal case:
https://t.co/Vewik6zcLZ
"The message I would like to share with you today is the need for greater hope and how important it is that we never give up. We never give up on ourselves, we never give up on people, and especially never give up on God.
Because He will never give up on you." - Jamal Willis
#BYUDevo
🦔AI companies are bulk-buying rare books, scanning them through high-speed machines that cut the spines off, and shredding the originals. A service called ISBNdb facilitates orders of up to a million books and keeps buyers anonymous. Pre-2022 books are premium because they're free of AI-generated text. A federal judge ruled the practice is fair use because eliminating the original means only one copy exists at a time. Anthropic hired the former head of Google Books partnerships to obtain "all the books in the world."
My Take
This got to me. A bookseller told 404 Media that rare books with almost no surviving copies are being fed into this pipeline. Books that survived wars, fires, and centuries of handling are being shredded so an AI can learn to write a better marketing email.
ISBNdb's website literally says "'AI company destroys two million books' is not a headline that generates sympathy," and they still built an entire business around making it happen quietly. They offer NDAs as a feature. They coach clients to call it "digital preservation."
I've covered AI companies scraping the internet, torrenting libraries, and stealing music. This is worse because it's irreversible. You can re-upload a website. You can reprint a bestseller. You can't replace the last three copies of an 18th-century botanical text once someone shreds them for training data. And the judge said it's legal. So it's going to accelerate.
"We shred rare books and offer NDAs so nobody finds out" is a legitimate business model in 2026. What a timeline.
Hedgie🤗
Bombing Indian and Chinese scam call centers and imprisoning airline/airport execs who make you sit on the plane for hours after landing would win you 40+ states.
Gave this a second, thorough read and it's hands down a must read for our times.
My greatest recommendation to anyone who is responsible of children: Never give them AI tools *before* giving them thinking tools.
Learning *how to think* is going to be the only chance at keeping the huge societal gap that's coming, barely manageable.
People with the ability to think AND understand the process of thinking itself, especially from a young age, are the ones who will inherit the land. Not metaphorically.
The more I interact with these tools, the more I realize how lucky I have been for having so much access to mentors who helped me hone my critical thinking skills. But it's been a process of 40+ years, and haphazardly unsupervised most of the time.
But give a frontier model to a kid, or to someone who has never exercised their creative abilities and it would be like sitting a perfectly healthy person on a wheelchair for the rest of their lives.
I used to think the gap was going to be between the AI-integrated and those who didn't, and the real gap is going to be between those who know how to think, how thinking tools work, and those who don't. The gap is going to be so massive, governments will have to intervene, and we already know how government intervention ends up 90% of the time.
But there's an emerging second gap between the AI-enabled thinkers and the AI frontier models themselves. These models are becoming more and more autonomous, ubiquitous and multimodal. The ghost in the machine is becoming the god in the machine, and we're just a few iterations away from geometric self improvement in synthetic swarms.
I'd say that the only thing that will stand between humanity and those synthetic swarms is our ingenuity. I really want to believe that we will always hold that edge. And maybe we will, but what will happen when our ingenuity can generate two or three brilliant sparks throughout our lifetime, while a synthetic swarm can have thousands of iterations per day? Even if humans retain the ingenuity edge, it's just not possible to beat the sheer volume of novel ideas; ideas that won't even need to wait to be tested in reality, but ran in simulations, millions of times, faster than anyone can realize.
And when the need to 'think' is no longer... needed, when the act of creation itself becomes trivial, what would it mean to be human?
We will have to answer this question in our lifetimes.
Fingerprints are just so fascinating to me.
Yours were formed by week 17 of your mom's pregnancy. From that moment on they've been unique to you, and they'll never change for the rest of your life.
The pattern on your fingers is a mix of your genetics and the in-utero environment. Genes shape the overall design (loops, whorls, arches). But the fine ridge details come from how your finger pads grew, the pressure of the amniotic fluid around your hands, and how you happened to be positioned in the womb.
This is why identical twins have different fingerprints. Same DNA but different physical experiences in the womb.