← Founder Notes
Archive

Researchers found that anthropic, openai, and google encrypt their chain-of-thought blocks with one…

Yethikrishna ROriginal on Threads

researchers found that anthropic, openai, and google encrypt their chain-of-thought blocks with one shared key per provider, so replaying a trace from a strong model into a weaker sibling can recover the hidden reasoning in plaintext. the attack is called a decryption jailbreak and it works across sessions, users, and models.

encryption without key separation is just obfuscation with extra steps.

Context

The arXiv paper Stealing Reasoning Traces from Proprietary LLM APIs (2608.09867), submitted 10 August 2026, studies the encrypted or opaque reasoning blocks that Anthropic, OpenAI and Google APIs return to the client and require back for multi-turn continuity. It finds the blocks are compatible and interchangeable across sessions, users and models within the same provider's ecosystem, so a trace from a capable, heavily safeguarded model can be replayed into a weaker model from the same provider, which can be made to decode it. The paper calls this a decryption jailbreak and demonstrates distillation, credential and PII extraction, hidden prompt injection and jailbreaking uses. It scraped and decoded 315,320 reasoning blocks from public repositories, recovering 367 PII artifacts and 182 credentials.

How it compares

The finding is compatibility within one provider, with stated exceptions: for Claude, traces of any model can be replayed by any other except Fable 5's thoughts, for GPT the GPT-5.6 series can replay traces of all earlier generations, and for Gemini any model's traces can be replayed into any other. It is not across providers. One shared key per provider is the note's inference, since the paper text read states compatibility, not a shared-key mechanism, so the mechanism is unverified. No provider response or fix was inspected, and the paper is a preprint. Encryption without key separation is just obfuscation is the author's opinion.

Related work

Watch next

  • Provider mitigations and peer review.

Sources

  1. Stealing Reasoning Traces from Proprietary LLM APIs (arXiv 2608.09867)arxiv.org

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 18 September 2026 at 20:17 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/researchers-found-that-anthropic-openai-and-google-encrypt-Ddbr1DSDu4Y" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Researchers found that anthropic, openai, and google encrypt their chain-of-thought blocks with one…"></iframe>

More notes