Researchers decode 315,320 encrypted LLM reasoning blocks to extract 367 PII artifacts
Tool · Hugging Face · stat: 367 PII A new paper on Hugging Face exposes a critical vulnerability in how OpenAI, Anthropic, and Google handle encrypted client-side reasoning traces. By injecting…
Tool · Hugging Face · stat: 367 PII
A new paper on Hugging Face exposes a critical vulnerability in how OpenAI, Anthropic, and Google handle encrypted client-side reasoning traces. By injecting encrypted blocks from advanced models into weaker models, attackers force the weaker models to output the hidden chain-of-thought in plaintext. A scrape of public repositories successfully recovered 182 credentials.
Client-side state management exposes proprietary LLM reasoning to cheap extraction Startups exposing raw API session logs risk leaking sensitive user credentials hidden inside encrypted reasoning blocks.
Every claim ties to a primary source. See our methodology.