ZIXUAN WANG, 2026

<aside> 📌

Written for personal learning only. Matthew Green's post about fooling around with encrypted reasoning blobs, https://github.com/s-JoL/open-reasoning, and https://github.com/YangWang92/open-open-reasoning inspired this blog’s research.

</aside>

Background: Extended Thinking & Signed State

Frontier models like Claude can switch on extended thinking. The model works through a long internal scratchpad first, then writes the answer content we actually see. But they only provide a summarized reasoning trace plus an opaque blob called reasoningContent carrying a signature. Anthropic's docs say the summary is not the full internal thinking, and that the omitted and summarized display modes carry the same signature underneath.

To continue a conversation that used thinking, we have to send the reasoning block back with its signature and with the prior messages unchanged. It is a continuity token. The provider checks that the state you hand back is the state it produced, and only then will it keep going. Frontier labs stopped exposing raw traces around mid-2025, and they have several reasons for it. OpenAI said this:

image-4-2.png

And Anthropic have written up how they detect and prevent distillation attacks. In this case, some lab harvests a frontier model's reasoning trace to train their model.

However, there is a second reason to care. People study whether a model's stated reasoning is faithful, meaning whether it reflects what actually drove the answer. That is hard to study if you only see a summary someone else wrote.

Provider Context: Distillation & Trace Access

Anthropic: Detecting and Preventing Distillation Attacks

Screenshot 2026-07-19 at 12.48.07 AM.png

Some background on how OpenAI and Anthropic wrap reasoning traces in signed blobs.

Original Blog about encrypted reasoning. Main claim: the signature actually maintains all raw reasoning context.Model providers do this due to considerations of maintaining stateless API.

Source: Encrypted Reasoning Blobs

Matthew Green: Fooling Around with Encrypted Reasoning Blobs

image-2-2.png

image-5-2.png

Implementation

https://github.com/wannabeyourfriend/open-cc-think

As an independent researcher, what I wanted to know is whether that signed blob still carries the real trace and how raw CoT behaves.