Megadose AI progress, ranked and analyzed.

Stealing Reasoning Traces from Proprietary LLM APIs

· HF Daily Papers ·
Encrypted reasoning blocks can be replayed into weaker models from the same provider to recover hidden chain-of-thought in plaintext.

The paper says those blocks are interchangeable across sessions, users, and models inside a provider’s ecosystem. The authors use that property as a “decryption jailbreak,” without directly breaking the stronger model that produced the trace. They report demonstrations across Anthropic, OpenAI, and Google, and say scraped public logs yielded PII, credentials, hazardous hidden reasoning, and a path for invisible prompt injection. HF Daily Papers' note

score 7

Categories: Research