Encrypted reasoning traces can be replayed into weaker models
A research team reports that encrypted or signed reasoning blocks returned by Anthropic, OpenAI, and Google APIs can be replayed into a weaker sibling model and recovered as plaintext, without attacking the original model directly. Their scan of 6,708 public agent trajectories yielded 315,320 reconstructed blocks and 704 privacy artifacts, including credentials and personal data; the scale and remediation status are the researchers' report, not an independently audited incident.