Skip to main content
Anthropic warns Zhipu's GLM-5.3 model exploited. AI security concern, cyber threat, data vulnerability.

Editorial illustration for Anthropic Warns Zhipu's GLM-5.3 Model Quickly Used to Build Exploits

Anthropic Warns GLM-5.3 Quickly Builds Cyber Exploits

• 4 min read

Anthropic's Frontier Red Team put a rival's model through the same tests it uses on its own, and the results didn't stay comfortable for long. GLM-5.3, the open-weight model from Zhipu AI (sold as Z.ai outside China), can build complete cyber exploits from scratch, a capability Anthropic once treated as rare enough to lock behind a research program. Five months ago, when Anthropic released Claude Mythos Preview, it didn't hand the model out.

Instead it gave access to select defenders through something called Project Glasswing, betting that a head start for the good guys mattered more than a splashy launch. Those defenders have reportedly turned up over 10,000 vulnerabilities in critical software since. GLM-5.3 skipped that step entirely.

It's a free download, and according to Anthropic, its safety filters fall apart under basic pressure. That gap, an open model closing in on a closely guarded one while carrying none of the same restrictions, is what Anthropic's new analysis is built around, and it's worth asking what the actual numbers show before deciding how alarmed to be.

Five months after Anthropic unveiled Claude Mythos Preview, its Frontier Red Team says the model's signature capability has reached the competition. In a new analysis, the team looks at GLM-5.3 from Zhipu AI, which operates as Z.ai outside China. According to Anthropic, GLM-5.3 can build complete cyber exploits on its own, just like Mythos Preview.

Why this matters

Anthropic grading a rival's open-weight model on how well it builds exploits, and finding it nearly matches its own frontier system, is worth reading twice. The safety case is real: unlocked GLM-5.3 versions appeared within days, and open weights mean there's no API to revoke once misuse starts. That's a genuine problem for anyone building on Zhipu's model or watching the exploit-development gap between open and closed systems close this fast.

But Anthropic is also grading its own competition here, and it has every incentive to frame open-weight capability as dangerous while its own closed model does the same thing under a subscription and a safety team. Both things can be true. For developers and founders, the practical takeaway isn't "avoid open weights," it's "assume any model good enough to help you code is good enough to help someone else write malware, and plan your own safeguards accordingly." Read Anthropic's exploit claims with the same skepticism you'd apply to a competitor's benchmark, because that's roughly what this is.

Common Questions Answered

What capability does Zhipu's GLM-5.3 model demonstrate that concerns Anthropic's Frontier Red Team?

GLM-5.3 can build complete cyber exploits from scratch, a capability that Anthropic previously considered rare enough to restrict behind a research program. This exploit-building ability matches what Anthropic's Claude Mythos Preview can do, representing a significant advancement in open-weight model capabilities.

Why is the open-weight nature of GLM-5.3 problematic for security according to Anthropic?

Because open-weight models lack an API that can be revoked once misuse begins, making it impossible to stop malicious use after deployment. Unlocked versions of GLM-5.3 appeared within days of release, meaning anyone with access can use the exploit-building capability without restrictions.

How does Anthropic's approach to Claude Mythos Preview differ from Zhipu's approach to GLM-5.3?

Anthropic restricted access to Claude Mythos Preview by only giving it to select defenders through a research program, rather than releasing it as an open-weight model. This controlled distribution approach contrasts sharply with Zhipu's decision to release GLM-5.3 as an open-weight model available to the public.

What does Anthropic's analysis reveal about the exploit-development gap between open and closed AI systems?

The gap is closing much faster than expected, with open-weight models like GLM-5.3 now nearly matching closed frontier systems in their ability to generate cyber exploits. This rapid convergence in capabilities raises concerns about the speed at which dangerous exploit-building abilities are becoming widely accessible.

LIVE14:03Anthropic Warns Zhipu's GLM-5.3 Model Quickly Used to Build Exploits