SUBSCRIBE

Yes, researchers pulled the hidden reasoning out of Claude, GPT, and Gemini. No, it was not the token counts, and it is already fixed.

The paper is real and better than the viral summary. The viral summary is wrong about how it worked, and quietly skips the part where all three labs patched it.

01THE CLAIM
"We found a vulnerability in the APIs of every frontier AI company that extracts models' hidden reasoning traces, verified against billable thinking-token counts." [SOURCE ↗]

THE MOVE: RENTED HALO, the achievement is real, the drama around it is borrowed

TRUE, BUT6 SOURCES · LIVE 2026-09-05
RESEARCHERS TRACK RECORD1 CLAIM · 40/100 BS RATE →
3FRONTIER LABS DEMONSTRATED
315,320REASONING BLOCKS DECODED
0LABS THAT LEFT IT UNFIXED AFTER DISCLOSURE
Yes, researchers pulled the hidden reasoning out of Claude, GPT, and Gemini. No, it was not the token counts, and it is already fixed.
02THE CHECK

THE CLAIM. a team found a vulnerability in every frontier lab's API that leaks models' hidden reasoning, and you could verify it by matching the billable thinking-token counts.

THE CHECK. the paper is real and demonstrated across Anthropic, OpenAI, and Google. But the mechanism in the viral version is wrong. The token count did not leak the reasoning. The attack replays a strong model's encrypted reasoning block into a weaker, less-guarded sibling model, which transcribes it in plain text. Token-count matching only confirmed the recovered trace was exact.

THE TWIST. the biggest fact got left out of the thread. After the researchers disclosed it, all three providers deployed server-side mitigations. It is a real and clever result about portable reasoning blocks, reported as a live catastrophe after the fixes had already shipped.

03SAY THIS IN THE MEETING
"Real attack, wrong mechanism, already patched. It replayed reasoning into a weaker model. The token count only proved the copy was exact."

Researchers at the ELLIS Institute Tuebingen and the Max Planck Institute published 'Stealing Reasoning Traces from Proprietary LLM APIs' (arXiv:2608.09867, submitted August 10). The finding is genuinely interesting. Anthropic, OpenAI, and Google all return encrypted chain-of-thought blocks, and wit

🔒 THE FULL AUTOPSY · FREE WITH AN ACCOUNT

You just read the free check. Sign in free, a code by email, no passwords, and the rest unlocks: the evidence trail, the steelman and the rebuttal, all 6 sources with quotes and screenshots, and our on-record call.

This story is a stable, citable object. If you can falsify a verdict, tell us. Corrections are loud here.