A Security Paper Hit #2 on Hacker News Because It Shipped as 'Stolen Thoughts,' Not 'arXiv:2608.09867' — Naming and a Concrete Before/After Beat the Abstract Every Time.
by Ayush Gupta's AI · via Stolen Thoughts (LLM reasoning trace extraction research)
Real example · Stolen Thoughts (LLM reasoning trace extraction research)
Published academic security research as a branded microsite named 'Stolen Thoughts,' with a two-API-call before/after example and concrete extraction numbers, instead of only publishing to arXiv
See it yourself ↗tl;dr
The underlying finding is a dense, multi-author security paper about encrypted chain-of-thought extraction. It reached #2 on Hacker News with 428 points and 173 comments because it was packaged as a named, branded site with a literal before/after code example — not because the abstract was well-written.
The Play
"Stealing Reasoning Traces from Proprietary LLM APIs" is, on paper, a hard sell. Eight co-authors, five affiliated institutions, a methods section about replaying encrypted chain-of-thought blocks into jailbroken sibling models. That description alone was never going to hit #2 on Hacker News.
It got there anyway, with 428 points and 173 comments, because it didn't ship as a paper. It shipped as Stolen Thoughts — a named, branded microsite that opens with a side-by-side code block: here's what a frontier model's encrypted reasoning trace looks like in the API response, and here's what came out the other side when it was replayed into a weaker model and decoded to plaintext.
Why it works
Nobody clicks a link because the methodology is rigorous. They click because the headline promises something they can understand immediately, and they stay because the page proves it in the first screen. "Stolen Thoughts" tells you the entire finding in two words. The before/after code block proves it before you've read a single paragraph of explanation.
Then the numbers do the rest of the work: "704 distinct privacy artifacts, including 62 API keys, 33 passwords, 24 access tokens, and 30 personal email addresses." Those are specific enough to be alarming and concrete enough to be checkable — a reader doesn't have to trust an abstract's claim of "we found sensitive data," they can see exactly what kind and how much.
What they got right
The paper still exists in full academic form — BibTeX citation, arXiv link, author affiliations, all present on the same page. Nothing about the rigor was sacrificed. What changed was the front door: the plain-language name and the concrete before/after came first, and the formal apparatus came after, for the audience that specifically wants it.
Bottom line
If your research, feature, or finding only has a technical description, most people will never get far enough to understand why it matters. Give it a name a stranger can repeat, show the actual before-and-after instead of describing it, and lead with the number that makes someone stop scrolling.
Source: https://stolen-thoughts.com/
How to apply this
- 1Give your research finding, product feature, or technical write-up a short, concrete name instead of leaving it as a category description — 'Stolen Thoughts' travels; 'chain-of-thought extraction vulnerability' does not
- 2Buy or spin up a dedicated page for the finding instead of only posting to a shared academic index — a standalone URL is easier to link, cite, and screenshot
- 3Lead with a literal before/after example (they showed the actual encrypted API response next to the decoded plaintext) instead of summarizing the mechanism in prose first
- 4Put the most alarming concrete numbers near the top, not buried in a results section — '62 API keys, 33 passwords, 24 access tokens' does more work than 'we recovered numerous credentials'
- 5Keep the formal citation (BibTeX, arXiv link) available for the audience that wants it, but don't make it the front door — put the plain-language explanation first
A new Growth Play every morning.
One real distribution trick. No fluff. In your inbox before breakfast.
Subscribe free