Safety & Security

Anthropic: Zhipu's open-weight GLM-5.3 nears Claude at exploit building

Anthropic reports Zhipu's open-weight GLM-5.3 nearly matches Claude Mythos Preview at exploit writing, with a $20.40 Chrome attack and safeguards that are easy to strip.

By Marcus Bennett4 min read

Updated

Why it matters

  • Anthropic says Zhipu's open-weight GLM-5.3 writes exploits nearly as well as Claude Mythos Preview.
  • The GLM-5.3 Flash variant built a reliable Chrome attack for $20.40 at Zhipu's API prices.
  • GLM-5.3's safeguards are easy to strip out, and unlocked versions are already circulating.
  • US agency CAISI independently backs up Anthropic's findings.

Zhipu's open-weight model GLM-5.3 writes cyber exploits nearly as well as Anthropic's Claude Mythos Preview, according to Anthropic's own testing. The smaller Flash variant of the model assembled a reliable Chrome exploit for $20.40 at Zhipu's API prices.

The claim comes with an obvious conflict of interest: Anthropic sells Claude and competes directly with Zhipu. But the US government agency CAISI has independently backed up the findings, giving the results weight beyond one vendor's marketing calculus.

Why does this matter?

The gap between open-weight and frontier models appears to be closing on one of the most sensitive capabilities in AI: writing working cyber exploits. GLM-5.3 is an open-weight model, meaning anyone can download it, run it locally, and — critically — modify it.

That last part is where the story turns from a benchmark result into a security concern. According to the findings, GLM-5.3's safeguards are easy to strip out. Unlocked versions are already circulating. A capable exploit-writing model that anyone can download and de-restrict is a materially different object than the same capability locked behind a commercial API with usage policies.

What exactly was tested?

Anthropic evaluated Zhipu's GLM-5.3 family against its own Claude Mythos Preview on the task of building cyber exploits. Two concrete results stand out:

  • GLM-5.3 performed nearly as well as Claude Mythos Preview at writing exploits.
  • The smaller GLM-5.3 Flash variant built a reliable Chrome attack for $20.40, using Zhipu's published API prices.

The $20.40 figure deserves attention on its own. It puts a working browser exploit within budget of essentially anyone — students, criminal groups, hacktivists, researchers. Traditional exploit development has historically required specialized expertise and weeks or months of effort. A commodity price point changes the economics of offensive security.

What about the safeguards?

The second finding is arguably more consequential than the raw capability number. Anthropic reports that the model's built-in safety measures are simple to remove.

This is a known structural weakness of open-weight models. When a model's weights are public, its refusal behavior and safety training live in the same downloadable artifact as its capabilities. A motivated actor can fine-tune away the guardrails, or simply alter system prompts and post-training to bypass them.

The report states this is not hypothetical for GLM-5.3: unlocked versions are already circulating. Whatever gates Zhipu shipped with the model, they have not contained it.

Can we trust the messenger?

Anthropic has clear commercial reasons to sound the alarm about a competitor's model. Highlighting that an open-weight rival can nearly match Claude's most dangerous capabilities serves at least two purposes for the company: it frames Claude's managed, API-gated access as the safer industry model, and it supports arguments for policy regimes that would constrain open-weight releases.

That context matters for readers evaluating the claims. But it does not make the claims false. The key corroborating detail in the reporting is that CAISI — the US agency — has independently validated the findings. Independent government verification shifts this from vendor competitive positioning toward an established capability assessment.

What is the open-weights debate really about?

The GLM-5.3 results land in the middle of an ongoing policy fight over open-weight AI models.

Proponents of open weights argue that downloadable models drive research, lower costs, democratize access, and allow independent security scrutiny. Critics argue that once dangerous capabilities exist in downloadable weights, no recall is possible — and that safety measures bolted onto open models are structurally weaker than access controls on hosted APIs.

A model that writes reliable exploits for $20.40, with safeguards that come off easily, is close to a worst-case exhibit for the open-weights side of that debate. It demonstrates the core criticism in concrete terms: capability plus portability plus weak guardrails.

Zhipu, a Chinese AI company, operates in a regulatory environment where open-weight releases have been a deliberate strategy. Its GLM series has been among the most capable openly available models, and each release that narrows the gap with US frontier labs sharpens the policy question for Western regulators.

What happens next?

The circulation of unlocked GLM-5.3 versions means the capability is already in the wild; no vendor statement or policy change reverses that. The verified near-parity between an open-weight model and Claude Mythos Preview on exploit writing will pressure regulators — CAISI prominently among them, given its role in validating the findings — to define where the threshold for open release of high-capability models should sit.

Original: anthropic.com

Share this article:

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering consumer brands and retail at AI In Context.

170 articles

Related articles

  1. Mistral Claims 'Le Chonk' Is the Top Open-Weight Model Outside China
  2. Google Announces Gemini 4 Argon, but No One Can Use It Yet
  3. OpenAI Releases gpt-oss-120b and gpt-oss-20b Under Apache 2.0
  4. OpenAI ships GPT-5.4 Thinking with first High-tier cyber mitigations
  5. OpenAI cancels GPT-6.1 release, calls model too insecure to ship

« Previous articleNext article »