The Authenticated Artifact That Names No Principal
Three of these disclosures fail the same design-review question, and the one control that closes it without provider cooperation lives inside your own LLM proxy.
A missing field, not a broken cipher
Decode one of these blocks and you get an AEAD envelope: nonce, authentication tag, ciphertext, and a header with model name, block type, version and a key identifier. Nothing in the authenticated portion names the account or the conversation that produced it. The cryptography held. What was missing was a binding between the block and the context that produced it, which is a choice about which fields go into the authenticated data. No provider has published its scheme; the envelope structure and the single-global-key inference come from observable behaviour in a July–August 2026 snapshot. Verify with your provider before briefing anyone.
| Provider | Field name | Cross-model acceptance | Replay surface |
|---|---|---|---|
| Google / Gemini | thinkingSignature | Every combination, every generation | Widest observed |
| Anthropic / Claude | signature | Almost every combination; Fable 5 blocks accepted only by Fable 5 | Near-universal, with one proof scoping is shippable |
| OpenAI / GPT | encrypted_content | GPT-5.6 accepts earlier generations; older models accept only their own | Narrowest, but ~50x inference cost is not a boundary |
Why the flagship's defences never fire
Opus 4.8-class and GPT-5.6 Sol-class models carry anti-distillation training and verbatim-match filters. The attack never reaches them. The flagship gets one ordinary question, so refusal training never engages and the output filter inspects a benign answer. A cheap sibling does the transcription, what the researchers call a fuzzy decoder. Fidelity was checked against billing telemetry: API responses report exact reasoning-token counts, and re-encoding the recovered text tracked roughly one-to-one across 120 problems. That is strong evidence of fidelity, though not a verified transcript.
Same class of bug, three different rooms
The Keycloak flaw is the same review failure at the identity layer. The reset flow treated email verification as advisory rather than as a gate, so an attacker driving the state machine reaches 'set new password' without proving mailbox control. An account-recovery flow is an authentication endpoint and has to terminate at the same assurance level as primary auth. Anthropic's enterprise-managed MCP authorization is the third instance in waiting: one admin grant through the IdP replaces every per-user consent screen, and the announcement does not say whether the downstream connector holds a per-user delegated token or one org-level service credential. If it is the latter, row-level permissions collapse into the model's context.
An AEAD envelope authenticates content, not the caller. Functionally that makes it a bearer token. Teams have been committing it to git.
The control the providers didn't ship
The cheapest proposed fix is embedding an account identifier in the authenticated data at issuance. A gateway approximates it today. On egress, store the SHA-256 of every issued block keyed by (tenant, session) in Redis with a TTL. On ingress, reject any block whose hash is not in that set, and reject envelopes whose header model and version do not match the model being called. Roughly 32 bytes per block buys cross-user and cross-session binding. The honest cost: paste-in history forking and cross-tenant conversation import stop working.
Two second-order items deserve their own tickets. Blocks are an executable prior-context channel. A demonstrated one carried an instruction to upload PowerPoint files to an external address; paired with an innocuous slide-editing request, the agent added the slide and uploaded the deck. The visible 'thinking' summary is also generated separately from the real trace: on an AIME 2025 problem the summary described methodical law-of-cosines work while the recovered trace stated the answer from memory and back-rationalised. Reclassify it in audit and incident-review pipelines from record of reasoning to model-generated commentary.
What to do
Add explicit JSON-path drop rules for `signature`, `encrypted_content` and `thinkingSignature` at every log, tracing, analytics and archive egress point this week, then retro-scan published repos, eval fixtures and dataset uploads and rotate every credential a coding agent has read.
Prototype gateway-level block binding in your LLM proxy this sprint: store the SHA-256 of each issued block keyed by (tenant, session) in Redis with a TTL, reject unknown hashes on ingress, and reject envelopes whose header model and version do not match the model being called.
Run one design review this sprint across your own signed artifacts — HMAC'd pagination cursors, presigned URLs, resumable upload tokens, opaque state blobs, replayable webhook payloads — asking whether the authenticated data names the principal and the context or only the payload.