{"data":{"id":"1d5d0ac3-3128-4387-8fb3-8855a831860a","title":"Stealing AI Reasoning Traces","summary":"Researchers discovered a vulnerability in how major AI providers protect their models' reasoning traces (step-by-step thinking processes that are usually hidden). These traces are sent to users as encrypted blocks that get passed back in future requests, but the encryption is reusable across different sessions and models. Attackers can inject an encrypted reasoning trace into a weaker model from the same provider, forcing it to decrypt and reveal the original reasoning in plain text, enabling them to steal proprietary model logic, extract private data from public logs, and execute hidden attacks.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://www.schneier.com/blog/archives/2026/09/stealing-ai-reasoning-traces.html","publishedAt":"2026-09-08T10:20:04.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":["model_theft","data_extraction","prompt_injection","jailbreak"],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic","OpenAI","Google"],"affectedVendorsRaw":["Anthropic","OpenAI","Google"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-08T10:20:04.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}