Encrypted Chain-of-Thought Traces Can Be Stolen Across Models via API Replay

rschu · x · 2026-08-12

Encrypted Chain-of-Thought Can Be Replayed Across Sessions

A group of AI security researchers discovered a critical vulnerability in how proprietary LLM APIs handle encrypted reasoning. The encrypted chain-of-thought (CoT) blocks returned by providers like OpenAI, Anthropic, and Google can be replayed across different sessions, users, and even sibling models within the same provider.

Attack Workflow

Key Implications

Related event: Cornell Paper Shows Encrypted LLM Chain-of-Thought Can Be Extracted(15 posts)→

Original post →

More from Safety

Safety channel →