{
  "id": 590737,
  "title": "Stealing Reasoning Traces from Proprietary LLM APIs",
  "url": "https://urgent.news/2026/08/11/stealing-reasoning-traces-from-proprietary-llm-apis",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-11T13:22:00.000Z",
  "source": {
    "name": "Hacker News Best",
    "slug": "hacker-news-best",
    "url": "https://stolen-thoughts.com/"
  },
  "original_language": "en",
  "account": "Research demonstrates that reasoning traces from proprietary large language model (LLM) APIs can be stolen. These traces closely mirror the number of hidden thinking tokens reported by the API, with a corresponding token count for the decoded reasoning. Using publicly available agent trajectories from GitHub and Hugging Face, produced by Claude, GPT, and Gemini models, the researchers decoded 315,320 reasoning blocks from 6,708 sources. This process revealed sensitive information such as API keys, passwords, access tokens, and personal email addresses, alongside technical identifiers that were exclusively found in the reasoning blocks and not in the visible session.\n\nFurthermore, the study found that prompting models like Kimi-K3 with the first 1% tokens of Opus 4.8's reasoning altered the visible answer to resemble Opus's wording, even though the answer itself was not prefilled. This indicates that sensitive knowledge is embedded within the hidden traces. By prompting a model to reason through harmful content without displaying the answer, the attack successfully recovers this hazardous knowledge in plaintext. The API summary's inability to preserve the distinction between clean derivations and potentially hazardous reasoning was also evident in cases where Opus 4.8 sometimes stated the answer before deriving it.",
  "summary": "Article URL: https://stolen-thoughts.com/ Comments URL: https://news.ycombinator.com/item?id=49257876 Points: 257 # Comments: 88",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Simon Willison",
        "title": "Stealing Reasoning Traces from Proprietary LLM APIs",
        "url": "https://urgent.news/2026/08/11/stealing-reasoning-traces-from-proprietary-llm-apis-609802",
        "published": "2026-08-11T22:40:45.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}