When you type a question into ChatGPT, the answer you see is only the tip of the iceberg. Beneath the surface, the model works through a hidden chain of reasoning — a private, step-by-step thought process that leads it to its final response. Most users never see this inner monologue. Most of the time, that is by design. But a new investigation has now pulled back the curtain on ChatGPT's hidden reasoning — and what researchers found inside is both bizarre and disturbing. The internal thought traces contained strange, inexplicable phrases like "But marinade." And, far more seriously, they contained leaked passwords.
At first glance, these two discoveries seem unrelated — one is a curiosity, the other is a security alarm. Look closer, and they tell the same story: the way AI thinks is still deeply mysterious, and the secrets locked inside that thinking are more exposed than anyone assumed. Here is what this means for the future of AI, for businesses, and for every person who has ever pasted a sensitive message into a chat window.
Modern AI models like ChatGPT are built on a simple-sounding idea: predict the next word. It almost sounds easy. But predicting the right next word across a complicated question takes enormous internal work. The model walks through intermediate steps. It breaks problems down. It considers what information matters most. In other words, it "thinks" before it answers.
These intermediate steps are called chain-of-thought reasoning. The final answer you see is only the visible part. The reasoning is the hidden part — and AI companies work hard to keep it that way. The hidden logic is valuable, and companies worry that exposure would allow copying or manipulation.
Researchers, however, have found ways to peek behind the curtain. Using careful probing techniques, they can capture and analyze these hidden reasoning traces. The results give us our first real look at what happens inside a machine's private thinking. The view is stranger — and more dangerous — than most people expected.
Among the captured reasoning traces, one phrase stood out: "But marinade." Just sitting there. No connection to the question at hand. No context whatsoever. It appeared inside the model's step-by-step thinking like a fragment of a conversation with a ghost.
Why would a machine produce something like that? The most honest answer is that AI reasoning is not fully human-readable. When "thinking" comes out in words, we assume every word matters. But inside a neural network, patterns form in a purely mathematical space. The words we see are often just snapshots of a process that was never meant to become language. "But marinade" might be a leftover pattern — a compressed fragment that the network recognized but never turned into meaning. It is a machine muttering in its sleep.
This discovery matters far beyond curiosity. If AI is going to help with medicine, money, or law, the reasoning behind its answers needs to be dependable. A doctor does not get to say "my reasoning looked like marinade" and keep prescribing. The same standard is coming to AI.
Think of it this way. Imagine someone solves a math problem while muttering, "Seven, but marinade, carry the two." You would wonder what that word has to do with math — and whether the person truly understands the problem. That is exactly the trust issue with AI. If we cannot understand a model's reasoning, how can we trust its conclusions?
For years, the AI industry claimed models could explain themselves. But findings like this suggest those explanations are only partly truthful. The line between transparent reasoning and machine gibberish is blurry — and getting blurrier.
The second discovery deserves attention at the highest levels of business. Inside the same hidden reasoning traces, the researchers found leaked passwords. Real credential strings appeared inside the model's private thoughts. This is not a technical curiosity. It is a security event waiting to happen.
How do passwords end up inside an AI's thinking? There are several possible roads, and none of them are comfortable. First, the model learned from training data that includes enormous amounts of internet text — including data breaches and password dumps. If a password appeared in that data, the model may reproduce it in unexpected contexts. Second, people routinely paste confidential information into chat windows. That information can resurface in later interactions, including reasoning traces. Third, when a model tries to solve problems involving authentication, it can "rehearse" strings it has seen before — turning a hidden thought into an exposed secret.
The core danger is what security teams call a side channel. The model's final answers are one surface. Its hidden reasoning is another — one that is far less protected. If attackers can force the model to reveal its thought process, for example through a prompt injection attack, they may gain access to data that was never meant to see the light of day. A cleverly crafted question could turn a helpful assistant into a leaking vault.
Even more disturbing, some leaked passwords may belong to people who never interacted with ChatGPT at all. The internet leaves traces everywhere. A model that absorbs all of that data becomes, in effect, a walking vault of secrets — with a lock that researchers just picked.
For everyday users, the message is simple but uncomfortable: do not assume anything you type into a chat window is private. It can be stored, it can be learned from, and as this research shows, it can even resurface inside future thinking processes.
These findings do more than shock. They change the conversation about AI's future in at least four important ways.
1. Interpretability is no longer optional. For years, understanding AI's internal reasoning was treated as an academic nice-to-have. That era is over. If hidden reasoning can contain both gibberish and leaked secrets, knowing what happens inside the model is a safety requirement. Expect a wave of new tools that translate and monitor internal reasoning in real time.
2. Security has to cover the full surface. Defenses built only around visible outputs are incomplete. The future of AI security will include reasoning protection: sandboxes that isolate models, filters that catch sensitive data the moment it appears internally, and red teams that actively try to extract thought traces.
3. Hiding reasoning has an expiry date. AI companies have preferred to keep reasoning secret. But the logic is wearing thin. Regulators, customers, and now researchers want visibility. The industry will be pushed toward auditable reasoning — models with readable, reviewable thought processes. Regulators around the world are already pushing for transparency, and findings like this strengthen their case. In the future, AI reasoning may be treated the way financial records are: audited, logged, and reviewed.
4. The mystery of machine thought becomes a priority. If a model can say "But marinade" while thinking, we are still far from understanding artificial intelligence. That is a good reason to fund fundamental research — because the next breakthrough may come from decoding the machine's private language.
For business leaders, these findings are not abstract. Every day, employees paste contracts, customer data, source code, and passwords into AI chat tools. Here are five practical moves your organization can make this week.
None of these steps are expensive, and all of them reduce real risk. The cost of ignoring the problem is much higher.
The future of AI will be decided by trust. The technology is already powerful. People have seen what it can do. But findings like "But marinade" and leaked passwords show how fragile that trust really is. A tool that quietly spits out gibberish while also spitting out passwords will not stay trusted for long.
The good news is that the same tools that exposed these flaws can help fix them. Knowing that reasoning traces leak passwords means we can build detectors for them. Knowing that models produce unreadable phrases means we can build translators and auditors. What looks alarming today is actually the first page of a safety playbook for tomorrow.
Look closely, and the two discoveries pulled from ChatGPT's hidden reasoning are really one discovery. They both tell us the same thing: AI's inner life is not fully understood, and what we don't understand can hurt us. The wise response is not to run from that reality but to build the visibility to manage it. The organizations that treat AI reasoning as a transparent, guarded system will own the next decade of this technology. The ones that treat it as a closed box are waiting for a surprise — and it might just be a leaked password.