
Encrypted Chain-of-Thought Is Not Private: New Paper Decodes Reasoning Traces From Anthropic, OpenAI, and Google APIs
A new arXiv paper shows the encrypted reasoning blocks that Anthropic, OpenAI, and Google return to API clients can be replayed into weaker models from the same provider and transcribed verbatim. The authors decoded 315,320 blocks from public repositories and recovered 367 PII artifacts and 182 credentials.












