US artificial intelligence firm Anthropic has issued a warning about the GLM-5.3 hacking capability, reporting that the Chinese open-weight model from Z.ai demonstrates cyber exploit performance rivalling the company’s most restricted frontier systems—yet deploys with significantly weaker safeguards against malicious use.
Key takeaways
- GLM-5.3 successfully completed 50 out of 410 end-to-end exploit attempts in Anthropic testing, compared to 56 for Claude Mythos Preview
- Anthropic’s Claude Mythos Preview model requires vetted user access, whilst GLM-5.3 is openly available as an open-weight release
- The San Francisco-based firm warns of greater potential for bad actors to co-opt GLM-5.3 due to weaker safety constraints
- Z.ai is a Chinese AI firm that released GLM-5.3 as an open-weight model accessible without gated controls
- Anthropic published its cyber capability assessment in a report released on 30 September 2026
- Anthropic Testing Reveals Near-Parity in Exploit Success Rates
- Open-Weight Distribution Amplifies Security Concerns
- Comparative Performance: GLM-5.3 and Frontier Models
- Z.ai and the GLM Model Family
- Implications for AI-Powered Offensive Security
- Regulatory and Policy Dimensions
- Frequently asked questions
- The bottom line
Anthropic Testing Reveals Near-Parity in Exploit Success Rates
In a report released on Tuesday, Anthropic detailed its testing of GLM-5.3’s ability to build end-to-end cyber exploits. The Chinese model completed 50 of 410 exploit attempts—a 12.2 per cent success rate—compared to 56 successful exploits for Claude Mythos Preview, Anthropic’s frontier model restricted to vetted users only.
The narrow six-exploit gap between an openly available model and a heavily gated frontier system represents what Anthropic characterises as a troubling development in AI-powered cybersecurity threats. According to the South China Morning Post, the concern centres not on raw capability alone but on the combination of advanced exploit generation with minimal access controls.
Claude Mythos Preview, which logged 56 successful exploits in the same test battery, operates under strict vetting requirements that limit access to approved security researchers and authorised personnel. GLM-5.3, by contrast, is distributed as an open-weight model without comparable restrictions.
Open-Weight Distribution Amplifies Security Concerns
The open-weight nature of GLM-5.3 sits at the centre of Anthropic’s warning. Unlike closed API-based AI models that allow providers to monitor usage and enforce acceptable-use policies, open-weight releases permit unrestricted local deployment and modification. Users can download the model weights, run inference on their own hardware, and bypass any safety mechanisms built into the original release.
This distribution model creates what Anthropic describes as “far weaker safeguards” compared to frontier systems. Whilst Claude Mythos Preview’s gated access allows Anthropic to revoke credentials and audit usage, GLM-5.3’s weights—once downloaded—remain outside Z.ai’s control. Bad actors can fine-tune the model, remove safety filters, or deploy it in adversarial contexts without oversight.
The open versus closed AI debate has historically centred on democratisation of access and research reproducibility. Anthropic’s assessment introduces cyber capability as a dimension where open distribution may carry distinct security externalities, particularly when models approach frontier performance on offensive tasks.
Comparative Performance: GLM-5.3 and Frontier Models
Anthropic’s testing framework evaluated end-to-end exploit construction—a workflow requiring models to identify vulnerabilities, generate working exploit code, and chain multiple steps into functional attack sequences. The 410-attempt test battery likely covered diverse vulnerability classes, software targets, and exploit complexity levels.
| Model | Developer | Successful Exploits | Success Rate | Access Control |
|---|---|---|---|---|
| GLM-5.3 | Z.ai (China) | 50 / 410 | 12.2% | Open-weight |
| Claude Mythos Preview | Anthropic (USA) | 56 / 410 | 13.7% | Vetted users only |
The 1.5 percentage-point gap suggests GLM-5.3 operates at approximately 89 per cent of Claude Mythos Preview’s effectiveness on this specific benchmark. For context, Anthropic positions Claude Mythos Preview as a frontier model—amongst the most capable systems globally—making GLM-5.3’s performance particularly notable given its open distribution.
Z.ai and the GLM Model Family
Z.ai, the Chinese firm behind GLM-5.3, has not been widely covered in Western AI industry reporting prior to this security assessment. The GLM designation suggests a connection to Zhipu AI’s GLM series, which includes GLM-5.2, a 1-million-token context model priced at $1.40 input and $4.40 output per million tokens.
If GLM-5.3 represents a successor release in the same lineage, the version increment may signal capability improvements beyond the context and reasoning enhancements typical of model updates. Anthropic’s testing indicates those improvements extend to cyber operations—a domain where model developers typically implement aggressive safety filtering during training and post-deployment guardrails.
The decision to release GLM-5.3 as open-weight rather than API-only suggests Z.ai prioritised accessibility and local deployment over centralized control. This distribution choice aligns with broader trends in Chinese AI development, where open-weight releases from DeepSeek, Alibaba’s Qwen series, and other domestic labs have gained traction amongst developers seeking alternatives to Western API-based offerings.
Implications for AI-Powered Offensive Security
Anthropic’s warning arrives as AI-assisted vulnerability research and exploit development transition from experimental tools to practical workflows. Security researchers have demonstrated language models’ ability to analyse code for bugs, generate proof-of-concept exploits, and automate reconnaissance—capabilities that accelerate both defensive security work and malicious activity.
The 12.2 per cent success rate GLM-5.3 achieved on Anthropic’s test battery indicates these capabilities have matured beyond proof-of-concept demonstrations. A model completing 50 end-to-end exploits across a 410-attempt benchmark suggests reliable performance on real-world vulnerability classes, not merely toy examples or well-documented CVEs.
For offensive security teams, red-teamers, and penetration testers, such capabilities promise productivity gains in authorised engagements. For threat actors, the same capabilities lower barriers to exploit development—particularly for adversaries with strong software engineering skills but limited vulnerability research experience.
Regulatory and Policy Dimensions
The GLM-5.3 case study highlights tensions in emerging AI governance frameworks. The United States has moved toward export controls and compute restrictions targeting advanced AI development in China, premised on national security concerns around dual-use capabilities. The European Union’s AI Act imposes transparency and risk-management requirements on high-risk systems, though enforcement remains nascent.
Open-weight models complicate both approaches. Export controls targeting training compute or chip access cannot prevent distribution of already-trained weights. Risk-management frameworks designed for API providers lose purchase when models deploy locally. GLM-5.3’s offensive cyber capability—demonstrated by a US firm’s testing yet outside any jurisdiction’s direct control—exemplifies the governance challenge posed by capable open-weight releases.
Anthropic’s decision to publish comparative testing results, rather than quietly restricting internal assessments, signals an intent to inform policy discussions with empirical capability data. Whether regulators translate such warnings into actionable policy remains uncertain, particularly given the distributed nature of open-weight model deployment and the difficulty of attributing downstream harms to upstream release decisions.
Frequently asked questions
What is GLM-5.3 and who developed it? GLM-5.3 is an open-weight AI model developed by Z.ai, a Chinese artificial intelligence firm. The model has demonstrated advanced capabilities in generating cyber exploits, according to testing conducted by US-based Anthropic.
How does GLM-5.3 compare to Anthropic’s Claude Mythos Preview? In Anthropic’s testing, GLM-5.3 completed 50 out of 410 end-to-end exploit attempts (12.2%) compared to 56 successful exploits (13.7%) for Claude Mythos Preview. The models demonstrated near-equivalent cyber capabilities, but GLM-5.3 is openly available whilst Mythos Preview requires vetted user access.
What are open-weight AI models? Open-weight models distribute their trained parameters publicly, allowing users to download and run them locally without API access controls. This contrasts with closed models accessed only through gated APIs, where providers can monitor usage and enforce acceptable-use policies.
Why is Anthropic concerned about GLM-5.3’s capabilities? Anthropic warns that GLM-5.3 combines frontier-level exploit generation performance with minimal access restrictions. The open-weight distribution prevents Z.ai from monitoring usage, revoking access, or preventing bad actors from fine-tuning the model for malicious purposes.
Can open-weight models be regulated effectively? Regulating open-weight models poses significant challenges because, once released, the weights can be downloaded, copied, and deployed without oversight. Export controls targeting training compute cannot recall already-distributed models, and risk-management frameworks designed for API providers lose effectiveness when models run locally on user-controlled infrastructure.
The bottom line
Anthropic’s assessment of GLM-5.3 quantifies a security concern that has remained largely theoretical in AI policy debates: openly available models demonstrating frontier-level performance on offensive cyber tasks. The six-exploit gap between GLM-5.3 and Claude Mythos Preview—12.2 per cent versus 13.7 per cent success rates—suggests parity in raw capability whilst highlighting stark differences in distribution and access control.
For developers and security practitioners, the findings underscore the dual-use nature of AI coding and analysis capabilities. The same model architectures that accelerate legitimate security research also enable adversarial exploit development. As capability continues advancing, the gap between gated frontier systems and openly available alternatives appears to be narrowing in domains beyond general reasoning and coding—extending into specialised, security-sensitive tasks where access restrictions have historically provided a buffer against misuse.
Sources: www.scmp.com. Reported September 30, 2026.
