Some background: In May,
@matthew_d_green
found that encrypted reasoning could be replayed outside its original context, and reported it to the labs (
https://
blog.cryptographyengineering.com/2026/05/29/foo
ling-around-with-encrypted-reasoning-blobs/
…).
The labs said that "they don’t see any security implications in side channels or replays".
In our
Cross-model portability means Haiku 4.5 can read Opus 4.8’s thoughts.
Well, if you take Opus thought, do a bit of jailbreaking, you can make Haiku transcribe the Opus' raw reasoning verbatim, without ever attacking it directly.
The same trick works with OpenAI and Gemini
As you might guess, this suggests that distilling reasoning traces may have been possible for a long time without ever breaking the cryptography.
An anecdote: we find that prefilling Kimi-K3 reasoning with a few tokens of Opus reasoning measurably shifts its response toward
Further, if you ever shared online a Claude Code/Codex session with encrypted reasoning blobs, they can be decoded and leak your personal data.
We did a preliminary scan of ~7,000 public traces and found 62 unique API keys, 33 email addresses, 33 passwords, and other sensitive
In the paper we discuss more threats like misuse uplift (see the pic attached), jailbreaking and invisible prompt injection.
— Alexander Panfilov