If CoT wasn't stateless and you instead just got a reference which pointed to the CoT stored on the lab servers, the same vulnerability would still exist. Since you just need a weaker jailbroken model to read a smarter model's CoT. This being stateless or not doesn't really matter.
The stateless part is also important for enterprise customers that require zero data retention.
(they could scope CoT access per model, but then users couldn't switch models mid-session)