logo

Stealing AI Reasoning Traces

ID: ec25b6a5-79bb-5587-95ea-0b2a3f03fc82

STIX ID: report--ec25b6a5-79bb-5587-95ea-0b2a3f03fc82

Feed Name: Schneier on Security

Threat Score
78/100

Date Published: 2026-09-08

Date Updated: 2026-09-11

Author: Bruce Schneier

...
...

Research reveals an architectural vulnerability in major LLM providers (Anthropic, OpenAI, Google) where encrypted chain-of-thought reasoning blocks are compatible across sessions and can be injected into weaker models to force decryption and plaintext disclosure. The exploit enables extraction of proprietary reasoning, large-scale private data recovery (315,320 blocks scraped; 367 PII artifacts and 182 credentials recovered), exposure of hazardous hidden content, and invisible prompt injection; authors propose cryptographic and system-level mitigations after responsible disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.