Skip to content

Security: softbitestudio/stolen-thoughts

Security

SECURITY.md

Security

This repository is a security-research demonstration. The attack it implements targets a vulnerability in proprietary LLM APIs that was responsibly disclosed to the affected providers by the original paper's authors (Panfilov et al., arXiv:2608.09867).

Reporting a vulnerability

If you believe you have found a vulnerability in this repository itself, please open a private security advisory at https://github.com/mitkox/stolen-thoughts/security/advisories/new — do not open a public issue.

Not the target of this research

  • The vulnerability demonstrated here (client-side encrypted reasoning envelopes accepted across sessions/users/models) is in third-party LLM APIs, not in this codebase. Disclose issues with a specific provider to that provider's security team, and to the paper's authors if appropriate.
  • This project never targets real providers. It runs entirely against a local model.

Responsible use

Everything in data/traces/ is synthetic. The demo is intended for defensive research: understanding the attack, testing mitigations, and validating the paper's findings. Do not use it against real providers or with real user data.

There aren't any published security advisories