A new arXiv paper from teams including the University of Tubingen, Max Planck Institute, MATS and Snyk argues that encrypted chain-of-thought blocks from OpenAI, Anthropic and Google APIs are interchangeable across sibling models. By replaying a flagship model's ciphertext into a weaker model from the same provider, they recovered plaintext reasoning without jailbreaking the stronger system. Scanning public session logs at large scale, they also pulled credentials developers had unknowingly published inside opaque blocks. The authors say the labs were notified and shipped short-term mitigations. The caveat is that some leakage may persist, and the paper does not prove commercial distillation by any named rival.