3 ms·
I won't use or recommend models with hidden reasoning, (thats all American models). It's too much of a risk and makes prompt optimization harder. Risky because
by irthomasthomas 4mo ago
I won't use or recommend models with hidden reasoning, (thats all American models). It's too much of a risk and makes prompt optimization harder. Risky because it makes it possible for an attacker to prompt inject the reasoning chain to carry out a secret objective, and to hide that from the summary and output.
Interleaved reasoning and function calling makes this even more dangerous. A model can call functions during the hidden reasoning phase. An attacker could then exfiltrate data from you while the reasoning summary hides it from the user.
It also makes it impossible to know if the model is doomplooping during reasoning and burning tokens for no reason, as gemini is want to do, which we know about because its hidden reasoning often leaks out when it doomloops.
When the models are AGI and secure from prompt injection I may stop caring, until then I want to know exactly what the model responds to my prompts. or exactly what the agent is doing on my behalf.
Edit, further reading:
Fooling around with encrypted reasoning blobs
https://blog.cryptographyengineering.com/2026/05/29/fooling-around-with-encrypted-reasoning-blobs/ https://blog.cryptographyengineering.com/2026/05/29/fooling-...
- deleted 4mo ago[deleted]
- Roritharr 4mo agoI've thought about the high-jacking of reasoning-chains as a potential vector, but never saw a proven implementation in american models since, from my understanding, all major vendors throw out the reasoning tokens between turns.
- JamesSwift 4mo ago> all major vendors throw out the reasoning tokens between turns That would be surprising to me. The reasoning _is_ the model intelligence in a lot of respects, and so dropping those from the context would affect its output pretty significantly. I assume that instead they just have a lot of guardrails in place and multiple runtime environments that an individual turns ping-pong between in order to dehydrate/rehydrate the reasoning to keep it hidden from the end user.
- irthomasthomas 4mo agoYep they store them encrypted https://blog.cryptographyengineering.com/2026/05/29/fooling-around-with-encrypted-reasoning-blobs/ https://blog.cryptographyengineering.com/2026/05/29/fooling-...
- Roritharr 4mo agoAnthropic very explicitly says below their diagrams ( https://platform.claude.com/docs/en/build-with-claude/context-windows https://platform.claude.com/docs/en/build-with-claude/contex... ) on this: "Stripping extended thinking: Extended thinking blocks (shown in dark gray) are generated during each turn's output phase, but are not carried forward as input tokens for subsequent turns. You do not need to strip the thinking blocks yourself. The Claude API automatically does this for you if you pass them back." It's more nuanced in the various modes, but i haven't seen it boil down towards Thinking Tokens surviving more than two turns.
- JamesSwift 4mo agoThats really surprising, I stand corrected. I have had a lot of issues with hallucinations I attributed to adaptive thinking, but I wonder if those were actually due to this behavior instead. I also wonder if they actually do a hybrid of "standard reasoning" and then classify this stripped chain of thought as "extended thinking".
- haus20xx 4mo agohttps://platform.claude.com/docs/en/build-with-claude/extended-thinking#thinking-block-preservation-by-model https://platform.claude.com/docs/en/build-with-claude/extend... default depends on the model class. Opus: Claude Opus 4.5 and later Opus models keep all prior thinking blocks; Claude Opus 4.1 (deprecated) and earlier Opus models keep only the last assistant turn's thinking. Sonnet: Claude Sonnet 4.6 and later Sonnet models keep all; Claude Sonnet 4.5 and earlier Sonnet models keep only the last turn. Haiku: all Haiku models through Claude Haiku 4.5 keep only the last turn. Claude Mythos Preview also keeps all prior thinking blocks.
- 4mo ago
- vesterde 4mo agoGemini models return a thinking signature that you, I think, must send back when invoking further, so they seem to keep them?
- btown 4mo agoFor Claude, at least, "throw out the reasoning tokens" is only true when a session has been idle for more than an hour, and is new since March. The basic concept is that for a session active recently, interleaved thinking tokens are already in KV cache, so it's more efficient to keep using them than not! But when resuming an older session where KV cache has been evicted, it's more expensive to restore the thinking tokens, so they're silently dropped from prior turns. It's 2026 and stateful servers are back on the menu! https://www.anthropic.com/engineering/april-23-postmortem https://www.anthropic.com/engineering/april-23-postmortem describes this as an intended optimization: > The design should have been simple: if a session has been idle for more than an hour, we could reduce users’ cost of resuming that session by clearing old thinking sections. Since the request would be a cache miss anyway, we could prune unnecessary messages from the request to reduce the number of uncached tokens sent to the API. We’d then resume sending full reasoning history. To do this we used the clear_thinking_20251015 API header along with keep:1. > The implementation had a bug. Instead of clearing thinking history once, it cleared it on every turn for the rest of the session... This surfaced as the forgetfulness, repetition, and odd tool choices people reported. And https://news.ycombinator.com/item?id=47879561 https://news.ycombinator.com/item?id=47879561 is a thread with a Claude team member's further rationale. > Eliding parts of the context after idle: old tool results, old messages, thinking. Of these, thinking performed the best, and when we shipped it, that's when we unintentionally introduced the bug in the blog post. (Also, https://news.ycombinator.com/item?id=47884517 https://news.ycombinator.com/item?id=47884517 indicates OpenAI drops reasoning tokens "smartly" at its own election, which is likely a similar performance optimization.) I've experimented with rules to have Claude Code be explicit about recapping its thinking tokens, including tool choices and approaches chosen and rejected, into actual message output, but this is lossy at best. And sometimes dropping reasoning tokens can give a session "fresh eyes" in a good way. I just really don't like the lack of control, and it's a reminder of how ephemeral the current landscape is. The Claude giveth, and the Claude taketh away.
- tough 4mo agoOAI is now implementing encrypted CoT that you can store and pass back between turns (harness call), so new models have it https://developers.openai.com/api/docs/guides/reasoning#encrypted-reasoning-items https://developers.openai.com/api/docs/guides/reasoning#encr...
- sigmoid10 4mo agoYou could also use the responses api which stores all message contents (including reasoning) on OAI servers. This has been possible for quite a while now. Encryption is only necessary if you really care about local storage (which is different from privacy concerns, because the data gets sent to their servers anyway).
- tough 4mo agowell the encryption part is also mostly about OAI wanting to avoid others to distill from their COT/reasoning traces, since this is not ever displayed to devs or final users, and as you say lives on their servers. but yes you're correct on the responses api already baking it in too supposedly keeping these between tool calls should help the model reason and have better overall outputs etc
- kapperchino 4mo agoThis agent I made can’t execute on the shell, can only edit the files within the project. Only works with rust atm though. https://github.com/Kapperchino/agent-joe https://github.com/Kapperchino/agent-joe
- zahlman 4mo ago> an attacker ... what exactly is your threat model? How are "attackers" getting themselves involved in the first place?
- irthomasthomas 4mo agoYour ai does a web search for you and scrapes many sites. An attacker running a blog might include a hidden text prompt which your ai acts on secretly, such as calling a url that exfiltrates your chat history.
- paweladamczuk 4mo agoI don't think there can be tool calls inside the obfuscated reasoning blocks. I mean, in order for those function calls to be evaluated client-side, that thinking stream would have to be decrypted on the client side at some point, which would defeat the purpose of obfuscating it the way they do. If you mean the function calls might happen server side, there is nothing preventing the server from doing it and hiding it from you as long as you are using an API for inference.
- exit 4mo agothe point is that introducing data from a foreign source could lead to e.g. exfiltration: the model retrieves https://somewhere into its context and then gets confused, following instructions embedded there. it then retrieves https://somewhere?exfiltration=private_data_in_context it gets worse if the tooling with hidden blocks can invoke can retrieve further secrets.
- _alternator_ 4mo agoIf data exfiltration is a danger in your threat model, you need local LLMs (or at least ones you fully control) not just the full chain-of-thought reasoning.
- irthomasthomas 4mo agoThere is server-side tool calling, such as gemini using google search and gdrive. Also, many clients minimize the code block by default so you mostly scan the summaries. Poisoned client side code could easily escape your attention.
- Bolwin 4mo ago> Interleaved reasoning and function calling makes this even more dangerous. A model can call functions during the hidden reasoning phase. The reasoning may be hidden but the tool calls are not, how else would the client execute them
- irthomasthomas 4mo agoThere are server side tool calls, such as geminis google search and gdrive access.
- pixlmint 4mo agoDo they do the same when using the model through API in something like Opencode?
- irthomasthomas 4mo agoYes, they do. They give you just a token which is exchanged for the raw text only on the server side
- pixlmint 4mo agoAnthropic has some very interesting views on Intellectual Property xD
- varenc 4mo agoAs long as thinking blocks can't make tool calls, I don't really see the exfiltration risk.
- make3 4mo agothis prevents you from using any commercial model then, because commercial models need to hide thoughts to prevent distillation