Researchers found that anthropic, openai, and google encrypt their chain-of-thought blocks with one…
researchers found that anthropic, openai, and google encrypt their chain-of-thought blocks with one shared key per provider, so replaying a trace from a strong model into a weaker sibling can recover the hidden reasoning in plaintext. the attack is called a decryption jailbreak and it works across sessions, users, and models.
encryption without key separation is just obfuscation with extra steps.
Context
The arXiv paper Stealing Reasoning Traces from Proprietary LLM APIs (2608.09867), submitted 10 August 2026, studies the encrypted or opaque reasoning blocks that Anthropic, OpenAI and Google APIs return to the client and require back for multi-turn continuity. It finds the blocks are compatible and interchangeable across sessions, users and models within the same provider's ecosystem, so a trace from a capable, heavily safeguarded model can be replayed into a weaker model from the same provider, which can be made to decode it. The paper calls this a decryption jailbreak and demonstrates distillation, credential and PII extraction, hidden prompt injection and jailbreaking uses. It scraped and decoded 315,320 reasoning blocks from public repositories, recovering 367 PII artifacts and 182 credentials.
The finding is compatibility within one provider, with stated exceptions: for Claude, traces of any model can be replayed by any other except Fable 5's thoughts, for GPT the GPT-5.6 series can replay traces of all earlier generations, and for Gemini any model's traces can be replayed into any other. It is not across providers. One shared key per provider is the note's inference, since the paper text read states compatibility, not a shared-key mechanism, so the mechanism is unverified. No provider response or fix was inspected, and the paper is a preprint. Encryption without key separation is just obfuscation is the author's opinion.
Related work
- A new trick reveals AI models' inner thoughts (Wired, 11 Aug 2026) ↗Snippet only.
- Reasoning trace theft research note (Cloud Security Alliance) ↗Secondary, snippet only.
- Project page ↗Snippet only.
Watch next
- Provider mitigations and peer review.
Sources
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 18 September 2026 at 20:17 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →