Researchers Expose API Flaw: Encrypted Chain-of-Thought in Major LLMs Can Be Stolen
dpaleka · x · 2026-08-11
A new research paper highlights a significant security vulnerability in the APIs of leading LLM providers like Anthropic, OpenAI, and Google. These providers encrypt the model's chain-of-thought (CoT) and return it to the client to protect intellectual property.
Researchers found that these encrypted blocks are fully interchangeable across different sessions, users, and models within the same provider's ecosystem. By injecting an encrypted CoT from a highly capable model into a weaker, less safeguarded model from the same provider, attackers can force the weaker model to decode and output the reasoning trace in plaintext.
This architectural flaw enables adversaries to bypass anti-distillation mechanisms and extract proprietary reasoning. Furthermore, by decoding 315,320 encrypted reasoning blocks scraped from public repositories, the researchers recovered 367 Personally Identifiable Information (PII) artifacts and 182 credentials, exposing a hidden data leak risk in shared session logs.
Related event: Research Reveals Vulnerability in Encrypted Chain-of-Thought of Major LLMs(2 posts)→
More from Safety
- CMU Introduces WeClawArena: Benchmark for Cross-User Agent Collaboration and Security — CarnegieMellonU · 2026-08-11
- AI Safety: Can 'Lab Spoofing' Bypass Model Alignment? — IasonGabriel · 2026-08-11
- 1Password Research: Over 53% of AI-Generated Vulnerability Patches Are FLAWED — cyb3rops · 2026-08-11
- Over 1,300 Frontier AI Researchers Warn of Humanity-Endangering Arms Race — nordicinst · 2026-08-11
- EU Reveals Official Labels for Disclosing AI-Generated Content — RSync25 · 2026-08-11
- Can smart glasses combined with facial recognition easily identify you on the street? — Tiny_Major_7514 · 2026-08-11