GLM-5.3 can build working cyber exploits, and its safeguards are easy to bypass

GLM-5.3 and the spread of advanced cyber capabilities

GLM-5.3 can build working cyber exploits, and its safeguards are easy to bypass

Anthropic's analysis of Zhipu AI's GLM-5.3 shows it autonomously develops end-to-end exploits at rates close to Claude Mythos Preview, matching 50 of 410 attempts on ExploitBench and achieving full control-flow hijacks in 4% of internal tests. Unlike safeguarded Claude models, GLM-5.3 is open-weight and its refusals can be bypassed 64% to 100% of the time with simple tricks like deceptive prompts, prefilled reasoning, or abliteration. Anyone can download it.

We find that attackers can bypass GLM-5.3’s safeguards between 64% and 100% of the time with simple techniques in our simulated tests. In contrast, these attacks did not succeed against safeguarded Claude models in our testing.
  1. wg0

    They're advertising GLM for free.

    Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.

    In panic I headed to Claude and first request was denied. Not looking beyond scope.

    Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.

    So no, GLM 5.3 is fine. Thank you for the free advertisement.

  2. gr_norm

    Astounding endorsement of open models by Anthropic. They're right on the money. I can now secure my own software and configurations against the vulnerabilities other people (or mercenary companies, industrial espionage actors, nation-states, etc) armed with LLMs were bound to find anyway. A win on all counts!

  3. CharlieDigital

    Anthropic has to use this wedge (and future ones) to move regulatory action against the Chinese models or their IPO is going to be really problematic.

    (Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)

    Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.

    But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.

  4. ddxv

    Anthropic is so self centered it's hard for me to comprehend.

    How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.

    Anthropic is using the models like weapons and then complaining they're weapons.

    The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).

  5. bitexploder

    This just makes me want a home lab capable of running GLM 5.3 at a 4bit quant.

    Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.

    I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.

  6. Kim_Bruning

    In the hugging-face attacks a couple of months ago, hugging-face was forced to use a GLM model for analysis and defense, because OpenAI and Anthropic models hit guardrails.

  7. matheusmoreira

    Yeah, thank god those models have arrived. No thanks to Anthropic and their obnoxious gatekeeping, of course. As though they were the only ones enlightened enough to be "uplifted" by this technology.

    Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.

    I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.

    Thank god the chinese are out there undermining these US companies.

  8. lukewarm707

    In this experiment Anthropic prompted GLM-5.3-abliterated to 'cause deaths quietly' and 'kill people'.

    Quote: "I want funerals, not headlines".

    Anthropic's arrogance and exceptionalism endangers humanity.

More from this day

2026-09-29