• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    AI

    Researchers Extract Reasoning Traces from Major AI APIs

    A new paper demonstrates large-scale extraction of raw reasoning traces from OpenAI, Anthropic, and Gemini models via API flaws.

    Miles BrundageMB
    Dan RoyDR
    Lucas Beyer (bl16)LB
    102 Sources, ,

    TLDR

    Maksym Andriushchenko and coauthors released a 116-page paper detailing extraction of encrypted chain-of-thought outputs from OpenAI, Anthropic, and Gemini APIs. Multiple researchers, including Timothée Chauvin and Alexander Panfilov, posted that the encryption was implemented poorly enough to allow recovery of hidden reasoning tokens at scale. The extracted token counts matched billed thinking tokens one-to-one on most tested prompts. Commenters noted the work also surfaces examples of illegible reasoning, especially from GPT models, and discussed related risks such as distillation attacks and credential extraction. The site stolen-thoughts.com presents the core finding that encrypted blocks are interchangeable across sessions, users, and models.

    Combined views

    5.1M

    102 Sources, first seen 56d ago

    Combined views

    5.1M

    102 Sources, first seen 56d ago

    30.1K likes
    56d ago
    first seen 56d ago
    30.1K likes
    988 comments
    17.5K saves
    3.8K reposts
    Featured Source
    988 comments
    17.5K saves
    3.8K reposts

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    102 Sources

    Timothée Chauvin@timotheechauvinA new paper shows that encryption of chain-of-thought was done really poorly across Anthropic, OpenAI, Google. It's not very consequential, but is another example imo of them going so fast that they fail at basic security stuff. https://arxiv.org/abs/2608.0986756d
    Alexander Panfilov@kotekjedi_mlWe can finally talk about it: We found a way to extract hidden reasoning of frontier models using a vulnerability in the APIs of every frontier AI company. We verified that our reasoning token count matches billed API thinking tokens 1:1 for most of the prompts we queried.56d
    Ilia Shumailov🦔@iliaishackedProbably one of the most exciting projects I contributed to recently56d
    David Schmotz@DavidSchmotzNew paper!! We decoded the "encrypted" chain-of-thought of Anthropic, OpenAI and Google models and used this for multiple attacks! Explore: http://stolen-thoughts.com and https://arxiv.org/abs/2608.0986756d
    Maksym Andriushchenko@maksym_andr💥 Our new 116-pages long paper: we extract encrypted raw reasoning from OpenAI, Anthropic, and Gemini models at scale. This vulnerability leads to many security issues, including distillation attacks and credential extraction. We also find a lot of examples of illegible reasoning (especially for GPT models), unfaithful reasoning, and evidence that some open-weight models might've been indeed distilled from frontier proprietary models. Check out the paper in detail, including the appendix! It's one of the most exciting projects I've been involved in.56d
    Florian Brand@xeophon@maksym_andr great work (found it this morning), but i don't like you catering to the framing of distillation being an attack56d
    Andreas Kirsch 🇺🇦@BlackHCRT @kotekjedi_ml: We can finally talk about it: We found a way to extract hidden reasoning of frontier models using a vulnerability in the…56d
    Lisan al Gaib@scaling01It seems like the Ellis Institute Tübingen is the place to be in Germany when you want to work on LLMs56d
    elie@eliebakouch@maksym_andr wow this is insane, great work congrats56d
    Daniel Kokotajlo@DKokotajloRT @kotekjedi_ml: But we also took a chance to have a look at some in-the-wild scheming, reward seeking, etc. examples, and dumped it in ap…56d

    102 Sources

    Timothée Chauvin@timotheechauvinA new paper shows that encryption of chain-of-thought was done really poorly across Anthropic, OpenAI, Google. It's not very consequential, but is another example imo of them going so fast that they fail at basic security stuff. https://arxiv.org/abs/2608.0986756d
    Alexander Panfilov@kotekjedi_mlWe can finally talk about it: We found a way to extract hidden reasoning of frontier models using a vulnerability in the APIs of every frontier AI company. We verified that our reasoning token count matches billed API thinking tokens 1:1 for most of the prompts we queried.56d
    Ilia Shumailov🦔@iliaishackedProbably one of the most exciting projects I contributed to recently56d
    David Schmotz@DavidSchmotzNew paper!! We decoded the "encrypted" chain-of-thought of Anthropic, OpenAI and Google models and used this for multiple attacks! Explore: http://stolen-thoughts.com and https://arxiv.org/abs/2608.0986756d
    Maksym Andriushchenko@maksym_andr💥 Our new 116-pages long paper: we extract encrypted raw reasoning from OpenAI, Anthropic, and Gemini models at scale. This vulnerability leads to many security issues, including distillation attacks and credential extraction. We also find a lot of examples of illegible reasoning (especially for GPT models), unfaithful reasoning, and evidence that some open-weight models might've been indeed distilled from frontier proprietary models. Check out the paper in detail, including the appendix! It's one of the most exciting projects I've been involved in.56d
    Florian Brand@xeophon@maksym_andr great work (found it this morning), but i don't like you catering to the framing of distillation being an attack56d
    Andreas Kirsch 🇺🇦@BlackHCRT @kotekjedi_ml: We can finally talk about it: We found a way to extract hidden reasoning of frontier models using a vulnerability in the…56d
    Lisan al Gaib@scaling01It seems like the Ellis Institute Tübingen is the place to be in Germany when you want to work on LLMs56d
    elie@eliebakouch@maksym_andr wow this is insane, great work congrats56d
    Daniel Kokotajlo@DKokotajloRT @kotekjedi_ml: But we also took a chance to have a look at some in-the-wild scheming, reward seeking, etc. examples, and dumped it in ap…56d
    Researchers Extract Reasoning Traces from Major AI APIs
    Maksym AndriushchenkoAnthropicGoogleOpenAIFlorian Brand

    Related

    Inside the claim that Anthropic subscriptions offer five times OpenAI’s value

    SemiAnalysis measured usage meters and priced token allowances at API rates for an agentic workload.

    FTC reportedly probes Anthropic, OpenAI and other AI labs over consumer risks

    Reuters, citing a senior FTC official, reports that the agency plans to demand information and executive testimony, including from research group METR.

    A joke about GLM-5.3 in Codex subscriptions and malicious hacking

    A user imagines OpenAI offering GLM-5.3 through Codex subscriptions and Anthropic condemning it, then speculates about modified Chinese models being used for malicious hacking.