
Anthropic reports widespread distillation campaigns from international labs
A comprehensive report details nearly 200 million unauthorized exchanges targeting frontier artificial intelligence models. The findings shed light on the methods used to extract internal reasoning traces for external model training.
Published by Jin · 2 min read · 11 SEPT 2026
A report published in July 2026 details persistent distillation campaigns directed against United States frontier artificial intelligence models. The findings, compiled by Anthropic, outline sophisticated methods used by international organizations to harvest reasoning capabilities and training data.
The Mechanics of Distillation
Distillation attacks primarily focus on extracting the internal chain of thought from a model's response to various queries. While developers typically shield these reasoning traces from standard users, attackers have devised clever prompts to bypass these safeguards.

For example, some campaigns successfully tricked target systems by framing queries as translation tasks, instructing the model to output working memory in specific linguistic formats. Once acquired, these reasoning chains can be utilized to train smaller models in general logic and advanced problem-solving.
Scale and Attribution
Anthropic observed nearly 200 million exchanges linked to five separate campaigns over recent months. The largest wholesale distillation effort identified was attributed to Alibaba, accounting for 151 million exchanges between May and July 2026. This operation utilized 3,500 distinct accounts sharing a fixed extraction prompt to gather material for the Qwen model family.

A separate campaign originating from Moonshot AI generated hundreds of thousands of requests targeting the Opus model. These queries included analytical tasks involving surveillance footage and behavioral assessment, reflecting intense global competition in artificial intelligence development.
Industry Response
Both Anthropic and OpenAI have previously flagged unauthorized harvesting activities as competition in the sector intensifies. As developers continue to refine defenses against capability extraction, the ongoing tension highlights the growing value of proprietary reasoning traces in next-generation systems.
Source — Original announcement ↗
Worth a read?
Comments · 0