MechanismArticle · 2:00 — 3:00
Critical Thinking: The attack reuses a valid encrypted reasoning block by replaying it into a different request, placing it in an assistant/model turn, and prompting a weaker model to transcribe the attached reasoning.
The mechanism is fully described: obtain a legitimate encrypted reasoning block, replay it into another request to a weaker model from the same provider, prefill the model to transcribe the reasoning, sample repeatedly, discard refusals, and reconcile noisy transcriptions. ✦ AI generated
AINews host (unattributed editorial) · Latent Space · 2026-08-12 · original ↗
The technique is somewhat described in the paper: Obtain a legitimate encrypted/signed reasoning block from an API response. Replay that block into a different request—potentially another account/session—to a weaker model from the same provider. Place it in an assistant/model turn and prompt or prefill the weaker model to transcribe the attached reasoning. Sample repeatedly, discard refusals, and optionally reconcile multiple noisy transcriptions.
Read full article ↗excerpt · fair-use quotation
Around this claim
This moment responds to
explains mechanism → Critical Thinking: Encrypted reasoning blocks from frontier API responses can be decoded and ported to different models, sessions, and users, which dramatically improves open models and leaks personal data when shared publicly.AINews host (unattributed editorial) · Latent Spacerebuts → Critical Thinking: The trace-exposure vulnerability does not imply practical mass theft of chain-of-thought for model training; it is more a stateless distributed-inference protocol optimization than a confidentiality barrier.AINews Twitter recap (attributed to @vipulved) · Latent Spaceextends → Critical Thinking: The attack generalizes across model providers with concrete per-model templates, including bypassing an apparent ~50-token verbatim-output threshold via chunked continuations.AINews host (unattributed editorial) · Latent Space