Proprietary LLM providers encrypt their chain-of-thought reasoning to protect intellectual property — but the encrypted blocks they return are fully compatible and interchangeable across different sessions, users, and models within the same provider's ecosystem. That compatibility is a decryption oracle.
The attack injects an encrypted reasoning block from a strong, safety-trained model into a weaker, less-safeguarded model in the same provider's ecosystem and instructs it to decode and output the block verbatim. Four abuse paths are demonstrated: model distillation (steal proprietary reasoning to train a local model); private data extraction (other users' published trajectory blocks can be decoded — yielding 704 privacy artifacts from 6,708 real trajectories: 62 API keys, 33 passwords, 24 access tokens, 7 private keys); harmful content recovery (content hidden behind a safe visible answer is recoverable from the concealed reasoning block); and prompt injection hiding (attacker embeds malicious instructions in opaque reasoning, invisible to output-only monitors). The vulnerability is structural — it follows from the block-passing protocol design, not from a specific model's alignment failure.