Th

Thought Forgery, a new technique for jailbreaking LLMs

Hacker News

Thought Forgery, a new technique for jailbreaking LLMs

Hi HN, I'm an independent security researcher and wanted to share a new vulnerability I've discovered. My account is too new to submit the direct link, so I'm making a text post instead. The technique is called "Thought Forgery" (CoT Injection). It works by forging the AI's internal monologue, which acts as a universal amplifier for other jailbreaks. I've confirmed it works on the latest models from Google, Anthropic, OpenAI, etc. I'd be happy to share the link to the full technical write-up on GitHub in the comments if anyone is interested.

Share card

Actual performance

2points
6comments
Did not reach leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: model, google, new · Missing: mac, agents, macos
94%94% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Missing: supports, reddit linkedin, podcasting
73%73% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
TrustMRRLess likely to generate early MRR · Strong signals: google · Missing: mobile apps, ios, personal
42%42% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
Hacker NewsMay not resonate with HN audience · Strong signals: io · Missing: https docs, excited, just released
41%41% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
AppSumoMay struggle as an AppSumo deal · Missing: plus, platform, intuitive
40%40% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
18%18% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Missing: web3, chat, crypto
1%1% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

Kr
KraspAI Kompass – keep up with new LLMs53%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

KraspAI Kompass – keep up with new LLMs

Hacker News1
A
A Penny for Your Thought39%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

A Penny for Your Thought

Hacker News6
De
Dendron – A Hierarchical Tool for Thought41%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Dendron – A Hierarchical Tool for Thought

Hacker News313
If
If you thought, like me, that weinre requires PhoneGap, You're wrong37%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

If you thought, like me, that weinre requires PhoneGap, You're wrong

Hacker News1
GP
GPTCache – Redis for LLMs69%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

GPTCache – Redis for LLMs

Hacker News7
pr
prompttest – pytest for LLMs34%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

prompttest – pytest for LLMs

Hacker News2
Thought Reps
Thought Reps52%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Thought Log + Spaced Repetition

Indie Hackerscommitment-side-project
Th
Thought Engineering43%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Thought Engineering

Hacker News7
Th
Thought Log and Spaced Repetition53%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Thought Log and Spaced Repetition

Hacker News1
LL
LLMs can be susceptible to a new kind of malware65%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

LLMs can be susceptible to a new kind of malware

Hacker News17