Definition
Data exfiltration is the unauthorized extraction of sensitive information from a system, whether by an external attacker, a malicious insider, or an unintended leak through a model's outputs. In the context of recovered reasoning traces, it refers to real secrets — API keys, passwords, and personally identifiable information scraped from public agent transcripts — surfacing inside a model's internal reasoning, showing how training or logging pipelines can inadvertently smuggle private data into places it was never meant to reach.