The HN discussion and the wider write-ups are landing hard on the “encryption isn’t safety” point. explainX calls the scheme done poorly across all three providers and leads with the leaked PII and credentials; MagicTools hits the same nerve — secrets that surfaced only inside the reasoning blocks, never in the visible output. Simon Willison is the calmest of the three: he calls the cross-model replay “neat,” flags the prompt-injection variants as the scarier finding, and notes the providers appear to have already patched the reuse. The trend is a field realizing that “hidden” reasoning was a client-side promise, not a cryptographic one.

tags: [ agentic-ai ] [ llm-ops ] [ industry ]