Stolen Thoughts
Encrypted chain-of-thought blocks returned by Anthropic, OpenAI and Google APIs are interchangeable across sessions, users and models. We exploit this to decode hidden reasoning at scale.
Stealing Reasoning Traces from Proprietary LLM APIs Alexander Panfilov1 2 3 4* David Schmotz2 3 4* Ilia Shumailov5* Luca Beurer-Kellner6 Joachim Schaeffer1 Ameya Prabhu2 4 7‡ Jonas Geiping2 3 4‡ Maksym Andriushchenko2 3 4‡ 1MATS Research 2ELLIS Institute Tübingen 3Max Planck Institute for Intelligent Systems 4Tübingen AI Center 5AI Sequrity Company 6Snyk 7University of Tübingen *Equal contribution, order decided by dice roll · ‡Equal supervision TL;DR Proprietary reasoning can be recovered from its encrypted traces. Anthropic, OpenAI, and Google return encrypted chain-of-thought blocks…
saved by
related reading
- Stealing Reasoning Traces from Proprietary LLM APIsresearch.snyk.io
- Let’s talk about encrypted reasoningblog.cryptographyengineering.com
- [2608.09867] Stealing Reasoning Traces from Proprietary LLM APIsarxiv.org
- Stealing Reasoning Traces from Proprietary LLM APIsarxiv.org
- [2510.24941] Can Aha Moments Be Fake? Towards Quantifying Decorative and True Thinking in Chain-of-Thoughtarxiv.org
- [2603.07267] How to Steal Reasoning Without Reasoning Tracesarxiv.org
- Quantifying the Necessity of Chain of Thought through Opaque Serial Deptharxiv.org
- Tracing the thoughts of a large language model \ Anthropicanthropic.com
- Learning to reason with LLMs | OpenAIopenai.com
- As Rocks May Think | Eric Jangevjang.com
- How AI Is Learning to Think in Secretnickandresen.substack.com
- Thought Branches: Interpreting LLM Reasoning Requires Resamplingarxiv.org