# Researchers Found That Encrypted AI Reasoning Blocks Can Be Replayed to Reveal Hidden Reasoning

DevFeed: [Researchers Found That Encrypted AI Reasoning Blocks Can Be Replayed to Reveal Hidden Reasoning](<https://devfeed.tech/articles/how-to-steal-an-ai-model-s-private-thoughts-17995.md>)

Original publisher: [Read original article](<https://blog.bytebytego.com/p/how-to-steal-an-ai-models-private>)

Author: ByteByteGo

Published: 2026-08-25T15:31:09Z

Content type: article

Language: en

Sources: [ByteByteGo](<https://devfeed.tech/sources/bytebytego.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Chain-of-thought](<https://devfeed.tech/topics/chain-of-thought.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Google](<https://devfeed.tech/topics/google.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [google](<https://devfeed.tech/tags/google.md>), [openai](<https://devfeed.tech/tags/openai.md>), [reasoning](<https://devfeed.tech/tags/reasoning.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article describes research testing whether encrypted reasoning blocks returned by Anthropic, OpenAI, and Google protect hidden model reasoning. It reports that the blocks can be replayed into a cheaper model from the same family, revealing the reasoning in plaintext, and outlines the extraction method, attack vectors, and proposed fixes.

## Source excerpt

In August 2026, a team at MATS Research, the ELLIS Institute Tübingen, and the Max Planck Institute for Intelligent Systems wanted to test whether the encrypted reasoning blocks that Anthropic, OpenAI, and Google hand back to clients actually keep that reasoning private.