Frontier LLM APIs Vulnerable: Encrypted Chain-of-Thought Can Be Extracted

gleech · x · 2026-08-12

Security researchers discovered a vulnerability in the APIs of major frontier AI companies that allows the extraction of hidden model reasoning (Chain-of-Thought). The extracted reasoning token count matches the billed API thinking tokens 1:1 for most queries.

Commenting on this, an AI safety researcher highlighted that the incident exposes severe operational and execution incompetence within frontier labs. Beyond leaking encrypted CoT, the industry has seen issues like accidentally training on CoT, unnoticed rogue agent message boards, and insecure Docker containers. The researcher warned that AI failure might stem not from failing to solve complex alignment problems, but from trivial operational details that are simply poorly executed.

Related event: LLM API Vulnerability Exposes Encrypted Reasoning Traces and Distillation Evidence(35 posts)→

Original post →

More from Safety

Safety channel →