The Stolen Thoughts research paper, first submitted August 10, 2026, reports a vulnerability involving encrypted reasoning blocks returned by proprietary model APIs. Its central finding is that opaque client-side data can still expose sensitive information when replay and compatibility boundaries are insufficiently enforced.
The paper record and abstract describe the studied attack classes. The authors’ project page includes a September 30 mitigation audit reporting remaining exposure through third-party providers. Those are research findings about evaluated interfaces, not a claim that every current provider configuration is vulnerable.
Encryption and safe replay are separate properties
The paper concerns blocks that clients retain and pass back to a service. The researchers report that compatibility across sessions, users, or models can permit a weaker interface to expose material from another model’s trace.
The defensive lesson is about binding opaque state to its intended context. A developer should know whether a returned object is tied to a user, session, model, and approved operation. The fact that the object is unreadable to an ordinary client does not establish that it is safe to publish or replay anywhere.
Logs deserve review even when they look opaque
The researchers report recovering sensitive artifacts from publicly shared reasoning blocks. This makes debugging and reproducibility practices part of the trust boundary. A log can contain sensitive machine-readable state even when its visible prose looks harmless.
Do not publish raw session artifacts by default. Review the fields being retained, redact secrets, and minimize access to private inputs. If a previously public artifact may contain credentials, address the exposed credential rather than assume deleting a repository copy removes all risk.
Third-party routing can change the security assumptions
The September audit reports remaining extraction through third-party API providers. That qualification matters: the relevant implementation may include intermediaries and compatibility layers, not only the model developer’s direct endpoint.
Inventory the actual request path and ask where opaque state is stored, transformed, or replayed. A provider update should be verified against the application’s chosen route. Test results obtained through one interface do not establish the behavior of another route with different handling.
What to do without reproducing the exploit
Teams can inspect logging policy, session isolation, connector boundaries, and incident response without running attacks on systems they do not own. Request current mitigation information from the responsible provider and use authorized testing where needed.
Nerova’s assessment is that this research broadens the definition of sensitive AI data. Protect the full interaction artifact, not only the final answer. Preserve the paper’s tested scope and audit date when communicating the finding, and verify current behavior before claiming a vulnerability is fixed or universally present.