Illustration only Photo by Vishnu Mohanan on Unsplash
Stealing Reasoning Traces from Proprietary LLM APIs
Why it matters — This reveals a side-channel that leaks hidden chain-of-thought data, which can contain API keys, passwords, and personal information. Defenders must treat reasoning outputs as sensitive and consider binding them to the session to prevent replay.