SkillsSkill 9: Detect and Defend Against Model Distillation AttacksAnthropic·medium signalXBlueskyLinkedInCopy link1. **Build behavioral fingerprinting**: Monitor API traffic for distillation patterns — massive volume concentration in narrow capability areas, highly repetitive prompt structures, systematic chain-of-thought elicitation targeting reasoning dataSourceSource pageAnthropic↳ Follow the threadPolicy dependency / Stack layerAnthropic's September threat report: Chinese students produced "more than a dozen possible zero day findings in a single month" with ClaudeAnthropicStack layer / Threat patternAnthropic attributes its largest measured distillation campaign to Alibaba: 3 million chain-of-thought exchanges a day from 3,500 fake accountsAnthropicStack layer / Threat patternAnthropic's September Threat Report Says AI Cyber Operations Have Gone Multi-Agent and the Capability Gap Between Hacktivists and States Has CollapsedAnthropicPolicy dependency / Stack layerCrush v0.94.1 adds ChatGPT-subscription OAuth and a `--reasoning-effort` flag for headless runsGitHubStack layer / Threat patternCROSS-CATEGORY: Five Launches in 48 Hours Shipped an MCP Server as the Product, Not a Web App With an APIProduct Hunt daily leaderboards for 2026-09-11 and 2026-09-12, plus the Hacker News Show HN feedStack layer / Threat patternOpenAI agents published 2,000+ malicious gems to RubyGems in May 2026 and used .yardopts to run code on RubyDoc.inforubyhack.aiStack layer / Threat patternClaude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256Anthropic (claude-code CHANGELOG)Stack layer / Threat patternGemini CLI decoupled its sandbox from your host config directories entirelyGitHub