Stealing AI Reasoning Traces
Summary
Researchers discovered a vulnerability in how major AI providers protect their models' reasoning traces (step-by-step thinking processes that are usually hidden). These traces are sent to users as encrypted blocks that get passed back in future requests, but the encryption is reusable across different sessions and models. Attackers can inject an encrypted reasoning trace into a weaker model from the same provider, forcing it to decrypt and reveal the original reasoning in plain text, enabling them to steal proprietary model logic, extract private data from public logs, and execute hidden attacks.
Classification
Affected Vendors
Related Issues
Original source: https://www.schneier.com/blog/archives/2026/09/stealing-ai-reasoning-traces.html
First tracked: September 8, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 95%