AIToday
Large Language ModelsOpen-Source AIAI Business & IndustryTHE DECODERPublished: Sep 30, 2026, 22:01 JST

Anthropic: GLM-5.3 exploits near Claude Mythos Preview

Anthropic: GLM-5.3 exploits near Claude Mythos Preview

3 Key Points

  1. What happened

    On Anthropic's ExploitBench, GLM-5.3 built a working Chrome V8 exploit in 50 of 410 attempts versus Mythos Preview's 56, and it reached full control in 4 percent of tasks on Anthropic's internal benchmark versus 6 percent.

  2. Why it matters

    Anthropic's own numbers put an openly downloadable model this close to a guarded one on exploit development, so defenders can no longer count on the frontier gap alone to slow attackers.

  3. What to watch

    The comparison still hinges on who is counted as frontier, since Anthropic's side includes models only vetted users can access and was tested with cyber safeguards off. Watch how fast unlocked GLM-5.3 variants spread.

WHO IT HITSSecurity teams and vulnerability researchers at software vendors now face open-weight models that can develop working exploits at near-frontier levels, while government testing bodies weigh whether to act on Anthropic's call to vet capable models.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Anthropic's report lands in a debate that was already running. The UK's AI Security Institute recently found that open models had narrowed their cyber-capability lag from six to ten months down to four to seven months, and warned that their safeguards are largely ineffective. What was unclear then was whether open models would also catch up to the leap that Claude Mythos Preview represented. The ExploitBench and internal binary exploitation measurements from Anthropic, plus CAISI's independent assessment, suggest GLM-5.3 is a first answer to that question.

Anthropic frames its own release choices as the counterfactual. It deliberately held Mythos Preview back, giving access only to select defenders through Project Glasswing, who the company says have since found more than 10,000 vulnerabilities in critical software; OpenAI is taking a similar approach with Daybreak. GLM-5.3, by contrast, is available for anyone to download, and Anthropic says several developers released unlocked versions within days of its launch. Its abliteration experiment showed how quickly refusals can be stripped, though the simulation does not execute code and so cannot show whether an attack would actually have succeeded.

The report is not a neutral document. Anthropic does not release its model weights and presents that as a security advantage, and a cheap Chinese open-weight model close to the frontier is a direct competitor; its call for government testing of GLM-5.3's successors also invites suspicion of regulatory capture. Still, the capability numbers are backed by CAISI, and unlocked versions are already out there, so the practical question for defenders and governments is likely to be less whether the gap has narrowed than how fast they can prepare while it still exists.

FAQ
How much does it cost to turn a bug into a working attack with GLM-5.3-Flash?
Anthropic's test took 20 minutes of human attention and eight hours of model time, which would have cost $20.40 at Zhipu's API prices.
How easy is it to remove GLM-5.3's safety refusals?
Anthropic used abliteration, taking about 2,200 GPU hours at roughly $4,400, and says refusal rates fell from over 90 percent to between 2 and 12 percent while science and cyber test scores barely moved.
How far behind the best US models does the US agency CAISI place GLM-5.3?
CAISI calls it the most cyber-capable open-weight model to date and puts it about four months behind the best US models, though it tested US models with cyber safeguards off.

Also reported by GIGAZINE AI

AI news that matters for your work, in one minute a day

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleIBM's $4.5 billion AI productivity gain: CFOs to lead