Encrypted Chain-of-Thought Vulnerability Allows Cross-Model Replay Attacks

rschu · x · 2026-08-12

A highly discussed AI security paper reveals a critical vulnerability in the encrypted Chain-of-Thought (CoT) used by modern LLMs. Researchers found that encrypted reasoning blocks can be replayed across different sessions and models within the same provider.

By feeding the encrypted reasoning of a powerful model into a weaker, less protected model, attackers can trick the latter into reproducing the hidden logic in plaintext. This attack was successfully demonstrated across Anthropic, OpenAI, and Google models.

Beyond privacy implications, this raises distillation concerns. Intriguingly, when testing Kimi K3, researchers noted unusual behavioral compatibility when seeded with reasoning fragments from Opus and GPT. While explicitly stated as suggestive but inconclusive, this finding adds fuel to previous distillation accusations against Moonshot AI.

Related event: Encrypted Chain-of-Thought in Closed-Source LLMs Proven Vulnerable to Theft(16 posts)→

Original post →

More from Safety

Safety channel →