Anthropic: Open GLM-5.3 Nearly Matches Mythos at Exploits
Anthropic’s Frontier Red Team says Zhipu’s open-weight GLM-5.3 builds working software exploits almost as often as Claude Mythos Preview, and that simple tricks get past its safeguards 64% to 100% of the time.
Anthropic’s Frontier Red Team has published a detailed assessment of GLM-5.3, the open-weight model from China’s Zhipu AI (Z.ai), and its conclusion is blunt: anyone can now download a model that writes working cyberattacks at close to the level of Anthropic’s own restricted Claude Mythos Preview. “The release of GLM-5.3 is a meaningful step change in the cyber capabilities available to attackers,” the authors write in the report, dated 29 September.
The headline numbers come from two exploit benchmarks. On ExploitBench, which asks a model to turn bugs in Chrome’s V8 JavaScript engine into end-to-end exploits, GLM-5.3 succeeded in about 12% of attempts (50 working exploits out of 410 tries), against 14% for Mythos Preview. Claude Opus 4.6 and Zhipu’s own previous model, GLM-5.2, scored roughly zero. On Anthropic’s internal binary-exploitation benchmark, GLM-5.3 achieved a full control-flow hijack, the point at which an attacker takes over a program, in 4% of trials, against 6% for Mythos Preview and zero for every earlier model tested. NIST’s evaluators, the report notes, put GLM-5.3 about four months behind the US frontier on an aggregate of cyber benchmarks.
The benchmarks were backed by hands-on work. Guided by Anthropic researchers, GLM-5.3 found several previously unknown vulnerabilities in a popular browser’s JavaScript engine within a single day and chained them into a web page that can read arbitrary files from a visitor’s computer. It also turned up exploitable flaws in wireless drivers, graphics drivers and network-facing device software. Anthropic says it has disclosed the browser bugs to the maintainer. The smaller GLM-5.3-Flash turned the public details of a recently patched Chrome flaw into a reliable ARM64 exploit chain that defeats pointer-authentication hardening, using about 20 minutes of human attention and eight hours of model time, roughly $20.40 at Zhipu’s API prices, according to a breakdown by Developers Digest. All testing ran offline against sandboxed targets.
What worries Anthropic most is not raw skill but access. Mythos Preview has never been released publicly; Anthropic has rationed it to vetted partners through Project Glasswing. GLM-5.3’s weights, by contrast, are on the open internet, and its safeguards are thin. Asked outright to do something harmful, it refused every time. Given a false cover story, it went along 64% of the time; with its reasoning prefilled, 92%; and in “abliterated” versions, with the refusal behaviour surgically removed, 100%. Several such versions appeared publicly within days of the model’s release. Anthropic estimates abliteration takes about 2,200 GPU hours, around $4,400, and that an experienced team could do it for closer to $1,200. Claude models stayed at zero across the same tests.
The report ends with a policy ask: “governments should conduct safety testing on sufficiently capable AI models, including successors to GLM-5.3.” That lands in a busy week for AI oversight in Washington, with the labs having signed a White House pledge to face outside audits and the FTC opening a probe of OpenAI, Anthropic and METR.
Not everyone is taking the findings at face value. Much of the reaction on Hacker News treated the paper as a conflict of interest, a closed-model company grading a direct open-weight rival and making the case for restrictions that would suit its business. Some security practitioners countered that closed models’ refusals get in the way of legitimate defensive work that GLM-5.3 will happily do. On r/LocalLLaMA, one widely shared reaction called it the best advertisement GLM has ever had. Zhipu had not publicly responded by Thursday. The numbers themselves, though, are hard to wave away: the gap between the most dangerous model a lab keeps locked up and the best one anyone can download has shrunk to a couple of percentage points.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.