They reference this paper which describes a method to decrypt reasoning traces (by sending the encrypted trace back to the model and asking it to transcribe it):
https://stolen-thoughts.com/paper.pdf
Interesting, but I suppose that's a hole that can be easily patched.
Interesting, but I suppose that's a hole that can be easily patched.