On 29 September Anthropic's red team published an analysis of GLM-5.3 from Zhipu AI (Z.ai), an open-weight model. Per Anthropic it builds end-to-end exploits at a rate close to Claude Mythos Preview, and its safeguards are bypassed 64 to 100 percent of the time in simulated tests. The assessment comes from a competitor and should be read that way.
- On ExploitBench GLM-5.3 reaches an end-to-end exploit in 50 of 410 attempts, Mythos Preview in 56 of 410.
- Abliteration, which strips refusals out of the weights, cost them about 4,400 dollars and barely dented capability.
- Anthropic also cites NIST CAISI: the most cyber-capable open-weight model released to date.
20.40 dollars.
That, at Zhipu's API prices, is what it would have cost the smaller GLM-5.3-Flash to build an exploit chain for two known Chrome bugs. Twenty minutes of human attention and eight hours of machine work. The test is Anthropic's, in an isolated environment, against targets they set up themselves.
The obvious first. Anthropic is assessing a competitor and has a stake in the conclusion. Mythos is closed, GLM-5.3 is a free download, and the text arrives at a call to give more defenders access to the strongest models. You read it, keeping that in mind.
But the numbers do not hang on their word alone. Per Anthropic, its capability findings broadly match CAISI's. The argument is less about whether the model can and more about who else can use it.
For defenders it means one thing: a capability that until now sat behind vetted-access programmes is now on the disk of anyone who downloads it. Anthropic also admits the other side, that the same model can help defenders. How much of each happens will show in misuse reports, not in benchmarks.
The headlines will say "Chinese model hacks". The more accurate version is different: a capability that in the spring existed in a single closed lab is now free; open weights cannot be called back.