GPT、Claude 遭遇窃听门:换个模型就能让思维链不再隐身?
TL;DR - Researchers reportedly recovered hidden reasoning from Claude, GPT, and Gemini APIs by passing encrypted reasoning blocks to compatible, more easily bypassed models. The finding matters because weak context binding could expose secrets, enable low-cost reasoning distillation, and carry invisible instructions into later agent runs.
- The attack does not break encryption; it exploits reasoning blocks that are insufficiently bound to the originating model, session, or account.
- Recovered-text lengths closely matched reported thinking-token counts, while agent traces revealed credentials and private information absent from visible conversation histories.
- Cross-model access could let inexpensive models extract reasoning produced by stronger models, reducing the cost of collecting high-value distillation data.
- In agent workflows, migrated reasoning can preserve hidden behavioral instructions, creating an opaque prompt-injection channel that influences future actions.