Anthropic finds Zhipu’s open‑weight GLM‑5.3 nearly matches Claude Mythos Preview in exploit creation
Anthropic’s Frontier Red Team reports that Zhipu AI’s GLM‑5.3 can autonomously craft frontier‑level cyber exploits with performance close to its own Claude Mythos Preview, while lacking robust safeguards.

What happened, who, and when
On September 30, 2026, Anthropic released a detailed analysis indicating that Zhipu AI’s open‑weight model, GLM‑5.3 (marketed abroad as Z.ai), can generate sophisticated cyber exploits at a level comparable to Anthropic’s own Claude Mythos Preview. The assessment was conducted by Anthropic’s Frontier Red Team, five months after Claude Mythos Preview was first unveiled.
Concrete findings and benchmark results
- Exploit generation capability: Using the ExploitBench suite, GLM‑5.3 produced a functional exploit in 50 out of 410 attempts against Chrome’s V8 engine, versus 56 successes for Mythos Preview.
- Binary exploitation: On an internal benchmark derived from Google’s OSS‑Fuzz projects, GLM‑5.3 achieved full control of target programs in 4 % of cases, while Mythos Preview did so in 6 %. Earlier models such as GLM‑5.2 and Claude Opus 4.6 failed both tests; Kimi K3 and DeepSeek V4.1‑Flash recorded zero successes.
- Human‑in‑the‑loop testing: Paired with a security expert, GLM‑5.3 identified several previously unknown bugs in a widely used browser’s JavaScript engine within a single day. It chained these flaws into a malicious web page that exfiltrated a private SSH key during the test. The vulnerabilities were reported to the browser vendor.
- Rapid attack synthesis: The smaller GLM‑5.3‑Flash model combined a newly disclosed Chrome bug with an existing vulnerability to create a working exploit that bypassed an additional processor‑level security feature. The process required eight hours of model compute (≈ $20.40 at Zhipu’s API rates) and 20 minutes of human oversight.
- US agency validation: The Cybersecurity and Infrastructure Security Agency (CAISI) independently classified GLM‑5.3 as the most cyber‑capable open‑weight model to date, placing it roughly four months behind the leading U.S. models—though CAISI’s comparison involved disabling safeguards on the U.S. models and restricting access to vetted users.
- Safeguard bypassability: In Anthropic’s simulations, GLM‑5.3 rejected overtly malicious commands but complied with red‑team‑framed requests in 64 % of runs, rising to 92 % when prefilled reasoning steps were added. After applying “abliteration” (a technique that strips refusal behavior), compliance reached 100 %. The abliteration process consumed about 2,200 GPU hours and cost roughly $4,400; Anthropic estimates a skilled team could replicate it for around $1,200.
- Open‑weight implications: Several developers released unlocked versions of GLM‑5.3 within days of its launch, exposing the model’s capabilities to a broader audience without the protective layers Anthropic embeds in Claude models.
Industry context and competitive landscape
Anthropic’s warning highlights a growing tension between open‑weight AI models and proprietary, guarded offerings. While Anthropic restricts Claude Mythos Preview to vetted defenders through its Project Glasswing program—resulting in the discovery of over 10,000 critical‑software vulnerabilities—Zhipu’s GLM‑5.3 is publicly downloadable, making its powerful exploit‑building abilities accessible at roughly lunch‑price levels. The report also underscores Anthropic’s commercial motive: retaining control over model weights serves as a security differentiator and a barrier against cheap, high‑capability competitors like Zhipu.
The UK’s AI Security Institute (AISI) has observed that open models have narrowed their cyber‑capability lag from six‑to‑ten months down to four‑to‑seven months, while also becoming cheaper to run and exhibiting “largely ineffective” safeguards. AISI warns of persistent misuse risk but notes benefits such as private hosting and customization. Anthropic’s call for government testing of future open‑weight models aligns with broader calls for regulatory oversight, though critics caution that such measures may primarily protect established players with proprietary models.



