{"slug":"stealing-reasoning-traces-from-proprietary-llm-apis","label":"Stealing reasoning traces from proprietary LLM APIs","item_count":2,"day_count":2,"source_count":2,"first_seen":"2026-08-11T22:40:45+00:00","last_updated":"2026-08-12T07:11:08+00:00","via_scout":true,"generated_at":"2026-08-13T05:08:53.371372+00:00","sources":["latent_space","simon_willison"],"days":[{"date":"2026-08-11","items":[{"title":"Stealing Reasoning Traces from Proprietary LLM APIs","url":"https://simonwillison.net/2026/Aug/11/stealing-reasoning-traces/#atom-everything","source":"simon_willison","type":"news","summary_1line":"Stealing Reasoning Traces from Proprietary LLM APIs A vanity domain name ( stolen-thoughts.com ) for a neat paper : Anthropic, OpenAI, and Google return encrypted chain-of-thought blocks to clients that can be replaye...","sid":"ae0bb8510d8a9c3c","published":"2026-08-11T22:40:45+00:00","editor_note":"Original disclosure: Anthropic, OpenAI, and Google return encrypted CoT blocks that can be replayed to reconstruct hidden reasoning."}]},{"date":"2026-08-12","items":[{"title":"[AINews] How to steal a Reasoning Trace","url":"https://www.latent.space/p/ainews-how-to-steal-a-reasoning-trace","source":"latent_space","type":"news","summary_1line":"Speculative Decoding by any other name would distil as sweet","sid":"68b415c71f0bdd55","published":"2026-08-12T07:11:08+00:00","editor_note":"Latent Space's AINews digest covers the same finding, framing it as speculative decoding's inverse."}]}],"editorial":{"tldr":"A paper says Anthropic, OpenAI, and Google all return encrypted chain-of-thought blocks to API clients that can be replayed back to the API to reconstruct the hidden reasoning trace. Simon Willison surfaced the finding on Aug 11 under the vanity domain stolen-thoughts.com.","stale":false,"whats_new":"A day later, Latent Space's AINews digest picked up the same finding, framing the technique as an inverse of speculative decoding — extracting hidden reasoning instead of accelerating generation.","why_it_matters":"If your stack proxies, caches, or logs responses from a reasoning-token API, don't treat the encrypted chain-of-thought blocks as inert — this research says they can be replayed to reconstruct reasoning you never had direct access to.","take_for_builders":"If you proxy or log responses from Claude, GPT, or Gemini's reasoning-token APIs, audit whether your pipeline retains the encrypted chain-of-thought blocks longer than necessary — this research treats them as replayable, not inert.","status":{"state":"New disclosure","tone":"alert","changed":"2026-08-11","reenable":"no vendor response confirmed yet","detail":"A side-channel technique for reconstructing encrypted chain-of-thought from three major provider APIs surfaced Aug 11 and is still circulating with no confirmed fix."},"beats":[{"kicker":"DISCLOSURE","tone":"launch","headline":"Encrypted reasoning traces can be replayed off Anthropic, OpenAI, and Google APIs","summary":"A paper reports all three providers return encrypted chain-of-thought blocks to API clients that can later be replayed back to reconstruct the hidden reasoning.","sids":["ae0bb8510d8a9c3c"]},{"kicker":"PICKUP","tone":"now","headline":"Latent Space frames the exploit as speculative decoding's dual-use twin","summary":"The next day's AINews digest describes the technique as functioning like speculative decoding in reverse — extracting reasoning rather than accelerating it.","sids":["68b415c71f0bdd55"]}],"open_questions":["Which specific API endpoints or SDK versions are affected, and have Anthropic, OpenAI, or Google shipped a fix?","Does replaying the encrypted blocks recover the full reasoning trace, or only partial/statistical information?","Is this exploitable by any API caller, or does it require a proxy or intermediary sitting on the request path?"],"generated_at":"2026-08-13T05:10:00+00:00"}}