User claims Codex subagent prompt encryption can be bypassed by spawning subagents differently

Aryvyo · x · 2026-09-09

Responding to theo's finding that OpenAI Codex encrypts prompts sent to subagents, user Aryvyo claims he accidentally discovered a bypass: getting the model to spawn subagents via another route exposes the prompts — an unconfirmed hole in OpenAI's anti-distillation protection.

Related event: Users Find Way to Bypass Codex's Encrypted Subagent Prompts(2 posts)→

Original post →

More from coding & agent

coding & agent channel →