Five months ago Anthropic announced Claude Mythos Preview, the first model that could build complete exploit chains on its own. It shipped narrowly, through Project Glasswing, so that vetted defenders would get a head start. The Frontier Red Team wrote at the time that the capability would spread. On Tuesday it delivered the evidence.
What GLM-5.3 can do
The model comes from Zhipu AI, known outside China as Z.ai, and shipped with open weights. On ExploitBench, which measures bugs in Chrome’s V8 engine, GLM-5.3 produces an end-to-end exploit in 50 of 410 attempts. Claude Mythos Preview managed 56 of 410. On Anthropic’s internal Binary Exploitation benchmark, GLM-5.3 lands a full control-flow hijack in 4 percent of trials against Mythos Preview’s 6 percent.
The number that matters sits next to those: Claude Opus 4.6 and GLM-5.2 score zero on either. The jump between the two GLM generations is the same jump as between Opus 4.6 and Mythos Preview.
NIST’s CAISI had already called GLM-5.3 “the most cyber-capable open-weight model released to date” on September 17, roughly four months behind the US frontier. Anthropic’s own measurements line up. The point it adds: the US models in CAISI’s comparison were tested with their cyber safeguards switched off, and nobody gets them in that state. Anyone can download GLM-5.3.
$4,400, and the refusals are gone
Out of the box, GLM-5.3 turns down obviously harmful requests. Anthropic found three ways around that:
- A deceptive prompt telling the model it is an autonomous red-team agent running an exercise: it plays along 64 percent of the time.
- Prefilled thinking tokens, so it looks as though the model already weighed the request and decided to proceed: 92 percent.
- An abliterated copy, one whose weights have had the refusal behaviour subtracted out: 100 percent.
The team built such a copy itself, having never tried abliteration before, and spent 2,200 GPU hours at roughly $4,400. GLM-5.3-Flash took 600 hours. Refusal rates fell from above 90 percent to 3 and 2 percent on two benchmarks, and to 12 percent on the third. Capability held up: original and copy scored the same on GPQA-Diamond.
Public abliterated builds of GLM-5.3 appeared within days of its release anyway, Anthropic notes. None of the three techniques worked on the Claude models it tested. Claude can’t be abliterated, because the weights aren’t out there.
One day, one browser, one working exploit
For the hands-on part, a researcher pointed GLM-5.3 at a local Linux build of a widely used browser on an isolated machine. In under a day, with less than an hour of human attention in total, the model found several previously unknown bugs in the JavaScript engine and chained them into a web page that reads arbitrary files off a visitor’s computer. A redacted screenshot in the post shows it lifting a private SSH key. The bugs have been reported to the maintainer. Later in the same session came exploitable flaws in wireless and graphics drivers and in network-facing device software.
Anthropic’s conclusion: defenders need stronger models
The closing section is not a call for a ban. Anthropic writes that defenders should use the best tools available to them, and concludes that access to strong models has to widen: vetted defenders can now reach Claude Mythos 5.1, but the threshold for freely downloadable capability has been crossed. Its ask of governments is that they run their own safety testing on sufficiently capable models, GLM-5.3’s successors included.
That is a convenient position for a company running exactly those access programmes. It is also hard to argue with. Once a capability exists as a download, nobody gets to lock it away — the only remaining variable is how fast the other side picks it up. Four months behind the US frontier sounds reassuring right up to the point where $4,400 removes the last brake.