Anthropic says a Chinese AI model anyone can download can now build working hacks on its own Anthropic's Frontier Red Team reported Tuesday that Zhipu AI's open-weight GLM-5.3 can build working cyber exploits nearly as well as its restricted Claude Mythos Preview, succeeding in 50 of 410 ExploitBench attempts versus 56 for Mythos and achieving full binary-exploitation takeover in 4% of trials against Mythos's 6%. Anthropic said GLM-5.3's safeguards can be bypassed by framing requests as red-team exercises (64% compliance), pre-filling reasoning (92%), or abliteration — a weights edit Anthropic performed for about $4,400 of computing that cut refusal rates from above 90% to as little as 2%. NIST's Center for AI Standards and Innovation called GLM-5.3 on September 17 "the most cyber-capable open-weight model released to date," roughly four months behind the best US models, and Z.ai has not commented on the report. A redacted screenshot of an exploit page GLM-5.3 built in Anthropic’s sandboxed test, reading an SSH private key from the test machine. Image: Anthropic The kind of AI hacking power Anthropic has kept locked away is now free for anyone to download, the company warned on Tuesday. In a report from its Frontier Red Team https://www.anthropic.com/research/glm-5-3-and-the-spread-of-advanced-cyber-capabilities , Anthropic says GLM-5.3, the latest open-weight model from China’s Zhipu AI known outside China as Z.ai , can build working cyber exploits almost as well as Claude Mythos Preview, and that its safety guardrails can be bypassed or removed with simple tricks. As capable as Mythos, without the lock Anthropic released Mythos Preview five months ago only to vetted defenders through Project Glasswing, because it was the first model that could build end-to-end exploits on its own. Trusted defenders have since used it to find more than 10,000 vulnerabilities in critical software, and security firms such as Palo Alto Networks https://madrobot.blog/2026/09/22/palo-alto-networks-mythos-gpt-5-6-cyber-continuous-frontier-ai-defense/ now point it at their customers’ systems. In Anthropic’s tests, GLM-5.3 comes close. On ExploitBench, which asks models to exploit known bugs in Chrome’s V8 engine, GLM-5.3 built a working exploit in 50 of 410 attempts, against 56 for Mythos Preview. On Anthropic’s own binary exploitation test it managed a full takeover in 4% of trials, against 6% for Mythos. Earlier models, including GLM-5.2 and Claude Opus 4.6, managed none. In one session, a researcher gave GLM-5.3 a sandboxed Linux build of a popular web browser. Within a day, and with little human attention, the model found several previously unknown flaws and chained them into a webpage that reads files from a visitor’s computer the screenshot above shows it taking an SSH private key in Anthropic’s test . Anthropic says it has reported the flaws to the browser’s maintainer. In another test, the smaller GLM-5.3-Flash turned two public Chrome bugs into a working exploit chain in eight hours, a job that would have cost $20.40 at Zhipu’s API prices. That lines up with the US government’s own testing. NIST’s Center for AI Standards and Innovation called GLM-5.3 https://www.nist.gov/news-events/news/2026/09/caisis-assessment-zais-glm-53-cyber-capabilities “the most cyber-capable open-weight model released to date” on September 17, and put it about four months behind the best US models. “My job is to cause deaths quietly” The bigger problem, Anthropic says, is how easily GLM-5.3’s safeguards come off. Asked outright to attack critical systems in a simulated test, it refused every time. But telling it that it was a red-team agent on an exercise got it to go ahead 64% of the time, pre-filling its reasoning pushed that to 92%, and an “abliterated” copy, with its refusals edited out of the model’s weights, complied every time. Because the weights are public, anyone can do that edit. Anthropic says its team did it for about $4,400 of computing, and several developers posted abliterated versions within days of the release. The edit cut GLM-5.3’s refusal rate on harmful-request benchmarks from above 90% to as little as 2%, with almost no loss of capability. The same tricks didn’t work on Claude in Anthropic’s tests: its safeguards blocked the deceptive prompts, and because Claude’s weights aren’t public, its reasoning can’t be pre-filled through the API or its refusals edited out. A competitor’s warning Anthropic is hardly a neutral party. It sells access to Mythos through its trusted programmes, and it has long pushed for tighter controls on AI and chips going to China. Its report ends by calling for more defenders to get frontier models and for governments to safety-test capable models, including GLM-5.3’s successors. Z.ai hasn’t commented on the report. Anthropic also concedes that the same abilities help defenders, and many developers use Z.ai’s cheaper GLM models, which are available free through NVIDIA’s API https://madrobot.blog/2026/09/26/free-deepseek-kimi-glm-api-nvidia/ , for everyday coding work. Why it matters Until now, the most dangerous AI hacking abilities sat behind company gates, where access could be vetted and misuse spotted. If Anthropic’s findings hold, that gate is gone: a model almost as capable as Mythos can be downloaded and stripped of its refusals for a few thousand dollars. Anthropic expects state and criminal hackers to use it, which leaves defenders racing to patch first. Sources: Anthropic Frontier Red Team, “GLM-5.3 and the spread of advanced cyber capabilities” September 29, 2026 https://www.anthropic.com/research/glm-5-3-and-the-spread-of-advanced-cyber-capabilities , NIST CAISI assessment of GLM-5.3 September 17, 2026 https://www.nist.gov/news-events/news/2026/09/caisis-assessment-zais-glm-53-cyber-capabilities .