cd /news/ai-safety/cantina-releases-an-open-weights-mod… · home › topics › ai-safety › article
[ARTICLE · art-144745] src=runtimewire.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Cantina releases an open-weights model trained for vulnerability research

Cantina released apex-flash-1, an open-weights cybersecurity model fine-tuned from GLM-5.3-Flash with 321 billion total parameters, in an October 4th post by co-founder and CEO Harikrishnan "Hari" Mulackal. Cantina's model card reports the model solved 40 of 60 held-out vulnerability tasks (66.7%) versus 43 of 60 for Claude Opus 5 High and 36 of 60 for untuned GLM-5.3-Flash, at an estimated evaluation cost of $2.38 versus $74.68 for Claude and $4.56 for the base model. The results are company-reported from a 60-task set drawn from 20 held-out vulnerability cases, and the weights are downloadable from Hugging Face, with Cantina recommending an agent harness such as Codex since no hosted, token-priced access is offered yet.

by read4 min views5 publishedOct 4, 2026
Cantina releases an open-weights model trained for vulnerability research
Image: Runtimewire (auto-discovered)

Hari Mulackal says Apex can make security-agent work cheaper; Cantina's own held-out test put it just behind Claude Opus 5 High at a fraction of the estimated cost.

        By [Ryan Merket](https://runtimewire.com/author/ryan-merket)
        · Published 

Primary source: [X](https://x.com/hrkrshnn/status/2106545457027793177)

Why it matters #

Cantina is testing whether a security-specific model, its own agent harness and proprietary evaluations can lower the cost of vulnerability work. Its published results are company-reported and narrow, but the open weights let others inspect and run the model themselves.

Cantina released apex-flash-1, an open-weights model fine-tuned for cybersecurity work, in an October 4th post by co-founder and CEO Harikrishnan "Hari" Mulackal (@hrkrshnn). The model is available to download from Hugging Face. Cantina recommends running it through an agent harness such as Codex; Mulackal said in a reply that the company does not yet offer hosted, token-priced access.

https://x.com/hrkrshnn/status/2106545457027793177 The release is a wager on economics as much as model capability. Cantina trained the model to read code, use tools, pursue exploits and verify their effects in a running target. Its model card describes apex-flash-1 as a reinforcement-learning fine-tune of GLM-5.3-Flash, with 321 billion total parameters. That makes the weights accessible to other developers, while leaving deployment and inference costs with whoever runs them.

Cantina's model card reports results from 60 tasks drawn from 20 held-out vulnerability cases. Apex solved 40 tasks, for a 66.7% pass rate; the card reports 43 of 60 for Claude Opus 5 High and 36 of 60 for the untuned GLM-5.3-Flash. Cantina estimated the cost of the 60-task evaluation at $2.38 for Apex, against $74.68 for Claude and $4.56 for the base model. Those are company-reported results from a small, company-designed test set, not an independent benchmark or evidence that the model finds vulnerabilities at that rate in production.

The comparison supports Cantina's central claim: a specialized model paired with its own training and agent systems could deliver useful security work for less than relying on a general-purpose hosted model. It does not establish how that cost advantage holds up across other targets, tasks or operating environments. Cantina's card says its evaluation used isolated environments and verifiers that checked the final state of each target. It recommends Codex as the harness and says the model was trained in production-like software and protocol environments.

Mulackal is building on a career spent close to software's failure points. Before co-founding Cantina and security firm Spearbit, he worked on the Solidity language and compiler at the Ethereum Foundation, according to his Devcon profile. That background in compiler and smart-contract security informs a move from reviewing code toward automating parts of vulnerability discovery and verification.

In his post, Mulackal argued that security work is becoming an economics problem: organizations need to find ways to identify and verify more vulnerabilities without spending as much on each investigation. He says Cantina has earned $1 million in bug bounties across programs and ranks first on HackerOne's US business leaderboard for 2026. Those are claims in his post, not independently audited performance figures. He also said Cantina's security harnesses process trillions of tokens a month, another company-reported measure that gives no cost, customer or outcome breakdown.

The company is making the model public while keeping its larger operating thesis focused on owning the full stack: evaluations, real-world security data, agent harnesses, post-training and inference. Mulackal criticized public cyber evaluations as poor proxies for work customers need, arguing that benchmarks built around known vulnerabilities in major software can diverge from flaws in everyday applications. Cantina says it built its own evaluations around offensive and defensive tasks it considers closer to customer work. That may give the company a more relevant internal measure; it also means outsiders cannot easily compare its claims with a neutral, common test.

The timing follows a broader change in how security teams assess AI's offensive potential. In a September 10th report, Anthropic described AI-assisted "exploit foundries", including workflows for vulnerability research and exploit development. Mulackal cited the report in his post as an example of security work being automated. The report documents Anthropic's own investigations and should be read as the lab's account of observed misuse, not as independent validation of Cantina's model.

Cantina emerged from stealth in July with an $8 million funding round led by Framework Ventures, bringing its reported total funding to $16.5 million, according to SiliconANGLE. The round backed a broader agentic security platform; the open model extends that strategy by giving users a way to run a security-specific component themselves. Neither the funding nor the model card discloses a valuation, and Cantina has not published revenue figures.

The repository was uploaded on September 30th, before Mulackal's October 4th release post. Its public availability therefore arrives with a concrete technical artifact and a test the company has chosen to publish, but the commercial case remains unproven in the disclosed numbers: the benchmark is narrow, hosting is not available from Cantina, and the post does not break out bounty income or customer results tied to Apex.

── more in #ai-safety 4 stories · sorted by recency
── more on @cantina 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/cantina-releases-an-…] indexed:0 read:4min 2026-10-04 · —