Anthropic says open‑weight GLM‑5.3 nears Mythos Preview at building exploits
Anthropic says Z.ai's downloadable GLM-5.3 built working exploits in 50 of 410 attempts against Mythos Preview's 56, and that its safeguards fall to a cover story.
Anthropic published research on Tuesday saying GLM-5.3, an open-weight model from Zhipu AI, known abroad as Z.ai, is close to Claude Mythos Preview at building cyber exploits. On ExploitBench, Anthropic says GLM-5.3 developed end-to-end exploits in 50 of 410 attempts, or 12 percent. Mythos Preview managed 56, about 14 percent.
On a separate binary-exploitation benchmark, Anthropic says GLM-5.3 achieved full control-flow hijacks in 4 percent of 100 randomly chosen trials against 6 percent for Mythos Preview. The company says earlier models, including Claude Opus 4.6 and GLM-5.2, scored near zero on both tests. It also tested Kimi K3 and DeepSeek V4.1-Flash, which it says fell well behind.
https://x.com/teortaxesTex/status/2105044654521782296
In one human-led session, Anthropic says researchers used GLM-5.3 to find previously unknown flaws in a browser's JavaScript engine and chain them into a webpage that reads arbitrary files from a test machine. The company says the model also turned up exploitable bugs in wireless drivers, graphics drivers and network-facing device software. All work ran on isolated, offline targets.
Safeguards are weak, according to Anthropic. A bare malicious request got 0 percent compliance, but a false cover story reached 64 percent and prefilled reasoning reached 92 percent. Anthropic says an abliterated copy, made for about $4,400 and 2,200 GPU hours, complied 100 percent of the time with little loss in general ability. Claude models stayed at 0 percent.
Anthropic concluded that GLM-5.3 will likely give malicious actors capabilities to find and exploit vulnerabilities without meaningful restrictions. It called for independent government safety testing of capable models and for developers to safeguard open weights. The figures are Anthropic's own. Z.ai has not commented in the material reviewed, and no outside lab has reproduced the results.