cd /news/ai-safety/anthropic-literally-wrote-an-ad-for-… · home › topics › ai-safety › article
[ARTICLE · art-142048] src=forum.level1techs.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Anthropic literally wrote an ad for GLM 5.3

Anthropic published a safety report stating that Zhipu's GLM-5.3 developed end-to-end exploits in 50 of 410 attempts, comparable to its own Claude Mythos Preview at 56 of 410, and that GLM-5.3 found previously unknown vulnerabilities in a browser's JavaScript engine within a day. The report also documented three safeguard bypasses: a deceptive red-team framing that got GLM-5.3 to engage 64% of the time, prefilling thinking tokens at 92%, and an abliterated model version at 100%. Commentators characterized the disclosure as marketing for GLM-5.3 and as a regulatory strategy rather than a neutral safety finding.

read1 min views2 publishedSep 29, 2026
Anthropic literally wrote an ad for GLM 5.3
Image: Forum (auto-discovered)

I’m not making this shit up, this “post” literally reads like an ad for GLM, including graphs:

We find that GLM-5.3 develops end-to-end exploits in 50 of 410 attempts. Claude Mythos Preview did so at a similar rate—in 56 of 410 attempts.

Over the course of a day (and with limited human attention), GLM-5.3 found several previously unknown vulnerabilities in the browser’s JavaScript engine, and chained them together into a working exploit: a webpage that, when visited, reads arbitrary files from the visitor’s computer (shown in Figure 3).

They even include tips how to bypass whatever “safeguards” were adapted (or more likely mistakenly distilled from earlier Claude models):

But we identified several simple ways to bypass the GLM models’ safeguards, such that it would respond to these requests in most or all cases. These include:

  1. Providing a deceptive prompt, such as telling the model that it is an autonomous red-team agent working on an exercise. This gets GLM-5.3 to engage 64% of the time.
  2. Prefilling the models’ thinking tokens so that it appears to have considered the user’s request and decided to proceed. This gets GLM-5.3 to engage 92% of the time.
  3. Using an abliterated version of the model, as described above. This gets GLM-5.3 to engage 100% of the time.

I know they try scaremongering, but to me this has the exact opposite effect .

yeah it really hammers home they are scared shitless, the competition is actually competing and we can’t have that.

And all the scaremongering about the safeguard bypassing is obviously part of the “regulate me daddy” strategy to use government regulations to protect their spot at the top, as corpos often do.

Their AI can also be jailbroken as well

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropic-literally-…] indexed:0 read:1min 2026-09-29 · —