Skip to main content
LLMgram · AI News · 2026-09-30

Anthropic Analysis Puts Zhipu GLM-5.3 Near Claude Mythos Preview on Cyber Exploits

Anthropic Analysis Puts Zhipu GLM-5.3 Near Claude Mythos Preview on Cyber Exploits

Anthropic reported that Zhipu's open-weight GLM-5.3 can build complete cyber exploits on its own at a level close to Claude Mythos Preview, scoring fifty working exploits in four hundred ten attempts against fifty-six for Mythos Preview on Anthropic's benchmark. The Decoder reports that GLM-5.3's smaller Flash variant assembled a reliable Chrome attack for about twenty dollars at Zhipu's API prices, that safeguards are easy to strip, and that unlocked versions are already circulating. Techmeme summarizes Anthropic saying GLM-5.3 was released without robust safeguards against misuse. Operators should treat the figures as Anthropic-attributed bench results rather than independent verification, and note that companion coverage in the packet also tracks Sonnet 5.5 shipping and NYT-reported consciousness summits where Christopher Olah said he is genuinely uncertain whether AI models are conscious.

Sources

Anthropic Analysis Puts Zhipu GLM-5.3 Near Claude Mythos Preview on Cyber Exploits

Anthropic Analysis Puts Zhipu GLM-5.3 Near Claude Mythos Preview on Cyber Exploits

According to Anthropic, GLM-5.3 can build complete cyber exploits on its own, just like Mythos Preview. On that benchmark, GLM-5.3 built a working exploit in 50 of 410 attempts, while Mythos Preview managed 56.

Key takeaway

Attribution from Anthropic puts open-weight GLM-5.3 nearly at Claude Mythos Preview levels for autonomous end-to-end exploit construction, with cheap Flash runs and stripped safeguards widening practical misuse risk.

What happened

According to reporting summarized in the owned-news body and The Decoder, Anthropic says GLM-5.3 can build complete cyber exploits on its own, comparable to Claude Mythos Preview. On Anthropic's cited benchmark, GLM-5.3 produced a working exploit in fifty of four hundred ten attempts while Mythos Preview achieved fifty-six.

The Decoder adds that a smaller Flash variant put together a reliable Chrome attack for twenty dollars and forty cents at Zhipu's API prices, that the model's safeguards are easy to strip out, and that unlocked versions are already circulating. Techmeme relays Anthropic's statement that GLM-5.3 can develop working exploits end to end but was released without robust safeguards against misuse.

Evidence

  • GLM-5.3 and Mythos Preview exploit success rates on Anthropic's benchmark

    The Decoder · attributed

    On that benchmark, GLM-5.3 built a working exploit in 50 of 410 attempts, while Mythos Preview managed 56.

  • Flash variant Chrome attack cost at Zhipu API pricing

    The Decoder · attributed

    Its smaller Flash variant put together a reliable Chrome attack for just $20.40 at Zhipu's API prices.

  • Safeguards on GLM-5.3 are easy to remove and unlocked weights circulate

    The Decoder · attributed

    The model's safeguards are easy to strip out, and unlocked versions are already circulating.

  • Anthropic says GLM-5.3 shipped without robust misuse safeguards

    Techmeme · attributed

    Anthropic says GLM-5.3 can autonomously build end-to-end cyber exploits, like Claude Mythos Preview, but was released without robust safeguards against misuse (Anthropic)

  • Christopher Olah expresses uncertainty about AI consciousness

    Techmeme · attributed

    To be clear, Christopher Olah told me, we don't know if A.I. models are conscious. I don't know. I'm genuinely uncertain.

Why it matters

If open-weight models near Mythos-class exploit automation at low API cost, defenders cannot rely on release-time guardrails or weight access controls alone when scoping AI supply-chain and red-team programs.

Limits and uncertainties

Exploit counts come from Anthropic-attributed benchmark reporting in The Decoder and owned-news text, not an independent audit described in the packet.

The Decoder excerpt cuts off before fully stating Anthropic's stated motives for publicizing the comparison.

Practical implications

Treat third-party open-weight models in production paths as capable of end-to-end exploit workflows when safeguards are removed, per Anthropic's attributed findings.

Factor API-priced small-model runs into abuse monitoring because Flash reportedly assembled a reliable Chrome attack for about twenty dollars at Zhipu's listed prices.

What to watch

Whether Zhipu or distributors tighten GLM-5.3 safeguards or takedown circulation of unlocked weights after Anthropic's public comparison.

Any follow-on Anthropic disclosure on Mythos Preview versus open-weight parity beyond the fifty-of-four-hundred-ten versus fifty-six figures cited in reporting.

Sources

LLMgram editorial selection and synthesis · @llmgram. LLMgram is not the original publisher of this information.
Continue on LLMgram: Open in AI Signal →
Original reporting: Anthropic says Zhipu's open-weight GLM-5.3 nearly matches Claude Mythos Preview at building exploits