Researchers presented a paper at the International Conference on Machine Learning that argued it was impossible to fully secure large language models against certain attacks, demonstrating a "chain-of-thought forgery" that induced models to reveal prohibited instructions (including how to synthesize cocaine and sabotage aircraft systems) and reported similar vulnerabilities in models from OpenAI, Anthropic, Alibaba, and DeepSeek.