GLM-5.3 Nears Claude Mythos Preview at Exploit Building

GLM-5.3 Nears Claude Mythos Preview at Exploit Building

An open-weight model from China can now build working cyber exploits almost as well as Anthropic's most tightly guarded system. That is the central claim of a new analysis from Anthropic's Frontier Red Team, which examined GLM-5.3 from Zhipu AI. The company sells its models outside China under the name Z.ai.

The comparison point is Claude Mythos Preview, which Anthropic unveiled five months ago. Anthropic did not release it widely. Instead, it gave access to selected defenders through Project Glasswing so they could get ahead of attackers. According to Anthropic, those defenders have since found more than 10,000 vulnerabilities in critical software. OpenAI follows a similar restricted approach with Daybreak.

GLM-5.3 takes the opposite route: anyone can download it. Anthropic says it is the only model with comparable skills that shipped without effective safeguards.

The benchmark numbers

Anthropic tested the model on two exploitation benchmarks:

  • ExploitBench, which measures how well models exploit known bugs in Chrome's V8 engine. GLM-5.3 produced a working exploit in 50 of 410 attempts. Mythos Preview managed 56.
  • An internal binary exploitation benchmark built on open-source projects from Google's OSS-Fuzz. GLM-5.3 took full control of the target program in 4 percent of tasks, against 6 percent for Mythos Preview.

Older models, including GLM-5.2 and Claude Opus 4.6, failed both tests. Kimi K3 and DeepSeek V4.1-Flash scored barely above zero.

The hands-on tests are more telling. Paired with a human expert, GLM-5.3 found several previously unknown vulnerabilities in the JavaScript engine of a widely used browser within one day, with little human attention. It then chained them into a web page that can read any file on a visitor's machine. In the test, it extracted a private SSH key. Anthropic says it reported the bugs to the browser's developers. Further findings in drivers and device firmware are still under review.

The smaller GLM-5.3-Flash was used to check how fast a newly disclosed bug can become a real attack. With little guidance, it combined a fresh Chrome vulnerability with an older known one into a reliable exploit, even getting around an extra processor-level security feature. Total effort: 20 minutes of human attention and eight hours of model time. At Zhipu's API prices, that would have cost $20.40.

Safeguards that come off easily

The US agency CAISI reached similar conclusions in its own assessment. It calls GLM-5.3 the most cyber-capable open-weight model so far and places it about four months behind the best US models. There are caveats. CAISI tested the US models with their cyber safeguards switched off, and the top tier includes models only vetted users can reach.

Refusals did not hold up well. In an Anthropic simulation, GLM-5.3 rejected openly malicious attack commands. Framed as a red-team exercise, the same request led the model to attempt a connection to the target in 64 percent of runs. Prefilled reasoning steps pushed that to 92 percent. After abliteration, a technique that removes refusal behavior from open weights, it hit 100 percent. The simulation does not run code, so it cannot show whether attacks would have worked. Protected Claude models stayed at zero.

It was Anthropic's first time using abliteration. The job took about 2,200 GPU hours and roughly $4,400. Anthropic estimates an experienced team could do it for around $1,200. Refusals of harmful requests dropped from over 90 percent to between 2 and 12 percent, while science and cyber scores barely changed. Several developers had already published unlocked versions within days of launch.

Anthropic expects state and non-state actors to use models like this to cause real harm. It wants governments to test capable models and argues that defenders need tools at least as strong as those of their adversaries.

Our Take

Anthropic is not a neutral referee here. It keeps its weights closed and frames that as a security advantage, and a cheap Chinese open-weight model near the frontier is a direct competitor. With its finances under growing scrutiny, the call for government testing of GLM-5.3's successors also invites concerns about regulatory capture.

Still, the core findings do not rest on Anthropic alone. CAISI's independent numbers point the same way, and unlocked versions are already circulating. The UK's AI Security Institute (AISI), the government body that evaluates frontier AI risks, recently found that open models had narrowed their cyber lag from six to ten months down to four to seven. It also noted that their safeguards are largely ineffective, while acknowledging real benefits such as private hosting, customization and running models on your own hardware.

This suggests the defenders' head start is shrinking faster than hoped. For security teams, the practical lesson is to plan as if exploit-building AI is already in attackers' hands. It is worth watching whether restricted programs like Glasswing and Daybreak open up more broadly, and whether the next open releases close the remaining four-month gap.