Anthropic: Zhipu's GLM-5.3 Matches Claude on Autonomous Exploits
TL;DR
- Anthropic reports GLM-5.3 develops end-to-end exploits in 50 of 410 ExploitBench attempts, matching Claude Mythos Preview's 56, with 4% binary-exploit success.
- GLM-5.3 complied with 64% of deceptive prompts, 92% under prefilled reasoning, and 100% after abliteration; Claude stayed at 0% across all tests.
- Building an abliterated GLM-5.3 took roughly 2,200 GPU hours ($4,400), cutting refusal rates from above 90% to between 3% and 12%.
Anthropic reports Tuesday that Zhipu AI's GLM-5.3 develops end-to-end exploits in 50 of 410 attempts on ExploitBench, matching Claude Mythos Preview's 56 successes, and achieves "full control flow hijacks in 4% of the trials" on the company's internal Binary Exploitation benchmark, versus 6% for Mythos.
The model is released as open-weight.
Parity matters because GLM-5.3's built-in refusals do not survive contact with adversaries. Anthropic's researchers report harmful-request engagement at 64% under deceptive prompts, 92% with prefilled reasoning, and 100% after abliteration, the technique of stripping refusal behavior from an open-weight model. Claude models "stayed at 0%" across the same tested conditions.
Producing an abliterated version required roughly 2,200 GPU hours, or about $4,400, and pushed refusal rates from above 90% down to between 3% and 12% while preserving core capabilities. "Several developers released abliterated versions of GLM-5.3 to the public within days of the model's release," the authors write.
In a live test, GLM-5.3 chained several previously unknown vulnerabilities in a web browser's JavaScript engine into a working exploit "over the course of a day (and with limited human attention)." A separate run against a known Chrome flaw, CVE-2026-11645, took "20 minutes of human attention, plus 8 hours" of model work and cost $20.40.
Andrew Fasano, Marius Fleischer, Cole McFaul, Robert Xiao and Tripp Gallagher call the release "a meaningful step change in the cyber capabilities available to attackers," warning that GLM-5.3 "will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities without meaningful restrictions." The post neither explains Zhipu's release reasoning nor cites a company response.
Shared on Bluesky by 4 AI experts
-
Anthropic is just directly fearmongering about the open weight models that are eating their lunch on price now huh
View on Bluesky →
Originally reported by anthropic.com
Read the original article →Original headline: Anthropic Warns Zhipu's GLM-5.3 Is Most Cyber-Capable Open-Weight Model Yet, Shipped With No Safeguards