safety
fact
bearish
Researchers discovered a vulnerability where encrypted reasoning state from proprietary LLM APIs can be stolen by replaying blobs across users and having smaller models decrypt the traces
The core bug sounds deceptively simple: providers return encrypted reasoning state so conversations can be resumed or forked. But those blobs can be replayed across users and sibling models. A smaller model can ask the provider to decrypt the trace, then repeat the hidden reasoning in plain text.
Machine Learning Street Talk28 Aug 2026