LLM Digest
Subscribe

AI Storyline

2 items · 2 sources · 2 days

View as JSON

Operational story trace

Stealing reasoning traces from proprietary LLM APIs

Current stateNew disclosurestatus changed Aug 11 · no vendor response confirmed yet

Latest change

A day later, Latent Space's AINews digest picked up the same finding, framing the technique as an inverse of speculative decoding — extracting hidden reasoning instead of accelerating generation.

Earlier contextThe story so far

A paper says Anthropic, OpenAI, and Google all return encrypted chain-of-thought blocks to API clients that can be replayed back to the API to reconstruct the hidden reasoning trace. Simon Willison surfaced the finding on Aug 11 under the vanity domain stolen-thoughts.com.

editor-curated · source-linked

Arc

Aug 11Aug 12 · now
DISCLOSURE · Aug 11
Encrypted reasoning traces can be replayed off Anthropic, OpenAI, and Google APIs
1 source · show source ▾
PICKUP · Aug 12
Latent Space frames the exploit as speculative decoding's dual-use twin
1 source · show source ▾

What to watch — open questions

  • Which specific API endpoints or SDK versions are affected, and have Anthropic, OpenAI, or Google shipped a fix?
  • Does replaying the encrypted blocks recover the full reasoning trace, or only partial/statistical information?
  • Is this exploitable by any API caller, or does it require a proxy or intermediary sitting on the request path?
How this thread was built
scout surfaced this threadeditor wrote the arc · 2 beatswatcher 1 status change

Storylines are threaded mechanically from the feed: stories that share a distinctive anchor across multiple days and sources. Each item links to its original source. The evidence trace, current state, and open questions are written by the editor routine and refreshed whenever a new beat lands.