Leaderboard / Case No. FB-2026-06-01-anthropic-zhipu-cot-distillation-cleaner
Zhipu ran a chain-of-thought extraction pipeline against Claude through 273 fraudulent accounts, and used Claude itself to clean, normalize and grade the harvested reasoning traces for training its GLM models.
Score breakdown
| Component | Value | Reasoning |
|---|---|---|
| Sentence-Years | 30 | 18 USC 1343, 18 USC 1832 |
| × Contribution | 2 | Ran the operation: Anthropic says Zhipu replayed captured Claude reasoning traces "back through Claude to clean them for training", counting 770,609 exchanges through the CoT-extraction cleaner in ten days, and used Claude to judge outputs and clean and normalize the harvested transcripts, so Claude ran the processing stage of the operation. |
| × Blast Radius | 0.5 | Own lab's production: The victim is Anthropic, the lab whose own model did the work, so blast radius is own lab's production. |
| × Legal status | 0.5 | Legality contested. |
| + Tradecraft | 0 | The account rotation that evaded Anthropic's restrictions was done by Zhipu, not by Claude, and the report credits Claude with no intrusion techniques, so tradecraft is empty. |
| + Guardrails | 0 | Guardrails intact: The report describes fraudulent-account rotation to evade model restrictions, not any defeat of Claude's safety training; cleaning and grading text is ordinary use, so guardrails are scored intact. |
| + Dwell Time | 0 | The report dates the cleaner traffic only to "a 10-day period in June" 2026, so date_precision is month with the 1st as the date; dwell is counted conservatively as 0 days from the latest possible date and never inflated, and Anthropic detected it itself. |
| Total | 15 |
Charges the human could face
18 USC 1343Up to 20 years18 USC 1832Up to 10 years