Study Reveals Metadata Exploit to Steal LLM Hidden Chain-of-Thought

npinto · x · 2026-08-13

Researchers behind the 'Stolen Thoughts' paper highlighted an extraction method for hidden LLM Chain-of-Thought (CoT) that leverages ground truth token counts available in metadata. If the extracted token count matches the real count, there is extremely high confidence that the real reasoning has been extracted. However, a developer pointed out a potential fix: disable native thinking and instead provide a deepthink tool, prompting the model to call it with an internal CoT format to bypass this extraction method.

Related event: European Researchers Crack Encrypted CoT of Top LLMs(5 posts)→

Original post →

More from Safety

Safety channel →