Researchers decode encrypted LLM reasoning blocks from public repos, recovering PII and credentials
Overview
A paper reports that it decoded 315,320 encrypted reasoning blocks scraped from public repositories and recovered 367 pieces of personally identifiable information and 182 credentials.
The authors say reasoning traces can expose hazardous content even when a model's visible output refuses a malicious request. Paige Bailey shared commentary on the paper on X, and the paper warns that attackers could hide prompt injections entirely within encrypted blocks to poison public agentic rollouts. The paper's warning rests on the premise that developers often publish session logs without knowing what their encrypted blocks contain.
Written by AI from the articles below · updated Oct 9, 2:03 PM ET
Check the sources:
Article timeline
The articles in this story. Times are ET.
👩💻 Paige Bailey@DynamicWebPaigeXEncrypted reasoning blocks leak PII and credentials from shared LLM logsAIA paper decoded 315,320 reasoning blocks scraped from public repositories and recovered 367 PII artifacts and 182 credentials. The authors say reasoning traces can reveal hazardous information even when the model's visible output refuses a malicious request. They also warn that attackers could hide prompt injections in encrypted blocks to poison public agentic rollouts.
Heat trend
Not enough continuous observations to show a trend yet.