A free Chinese model builds hacks almost as well as the one Anthropic locked up. The gap NIST measured is bigger than the headline.
Anthropic says Z.ai's open GLM-5.3 built working exploits in 50 of 410 tries, against 56 for the Mythos model it rationed. NIST's own test, published twelve days earlier, shows the US lead is still large.

Five months ago Anthropic made a bet. It built a model, Claude Mythos Preview, that could write working exploits on its own, and instead of selling it to everyone it handed it to a vetted group of defenders under a program called Project Glasswing. The idea was to buy time. Hold the capability back long enough that defenders could patch before attackers had anything similar.
On September 29 Anthropic published a post saying the time is up. A model anyone can download, GLM-5.3 from China’s Z.ai (also known as Zhipu AI), now does the same trick almost as often.
The headline number is easy to repeat. The numbers around it are more interesting.
50 versus 56
On ExploitBench, a test built around known bugs in V8, the engine inside Chrome, Anthropic says GLM-5.3 built a working end-to-end exploit in 50 of 410 attempts. Mythos Preview managed 56 of 410. On Anthropic’s own internal binary exploitation test, GLM-5.3 hijacked a program’s control flow in 4% of tasks and Mythos Preview in 6%. Older models, including Claude Opus 4.6 and GLM-5.2, scored at or near zero on both.
Those are low success rates in absolute terms. Roughly one try in eight works. But a script doesn’t get tired, and an attacker only needs one try to land.
Anthropic also describes a test session where a researcher pointed GLM-5.3 at a sandboxed Linux build of a popular browser. In about a day, with little human attention, it found several previously unknown flaws in the JavaScript engine and chained them into a web page that reads files off a visitor’s computer. Anthropic says it reported the flaws to the maintainer.
What NIST found twelve days earlier
The US government’s testing arm, NIST’s Center for AI Standards and Innovation (CAISI), published its own GLM-5.3 assessment on September 17. It calls the model “the most cyber-capable open-weight model released to date.” It also says GLM-5.3 trails the US frontier by about four months across its cyber benchmarks.
Anthropic says its findings “broadly match” CAISI’s. They do on the ranking. The raw scores are a different picture:
| CAISI benchmark | GLM-5.3 | Best US model tested |
|---|---|---|
| SEC-Bench Pro (find a bug and crash it) | 40.4% | 90.2% |
| ExploitBench (score out of 16) | 9.8 | 16.0 |
| ExploitGym, userspace | 9.4% | 44.4% |
| CAISI OSS-Fuzz (private test) | 7.7% | 23.2% |
Best US model means the highest score among US models CAISI tested, including some released only to vetted users, and with their cyber safeguards switched off where that was possible. So GLM-5.3 is close to the model Anthropic rationed and a long way from the best one anybody has. Both things are true. Which one you hear depends on who is talking.
CAISI is also clear that it didn’t test models that exist but haven’t been released, which could be stronger still.
The safeguards were never the point
GLM-5.3 does refuse obviously harmful requests, at first. Anthropic then tested how long that lasts. With a made-up cover story, the model engaged with a malicious cyber order 64% of the time. With prefilled reasoning, 92%. After “abliteration”, a standard technique that edits a model’s weights so it stops refusing, 100%.
The abliterated version took Anthropic’s team, which says it had never done this before, about 2,200 GPU hours and roughly $4,400 of compute. Refusal rates on two public tests fell from above 90% to about 3% and 2%. On general science questions the edited model scored the same as the original. Anthropic adds that other developers published abliterated copies of GLM-5.3 within days of its release.
This is the part I’d weigh most. A safeguard on a model you can download is a suggestion. Anthropic notes that Claude can’t be edited this way because nobody outside the company has the weights, which is true and also convenient for a company that sells access to Claude. Take the comparison as a fair technical point from an interested party.
My read
I don’t think the lesson is “China is catching up in hacking AI.” The government’s own numbers say a four-month lag, and four months in this field is a long time. I think the lesson is that rationing a capability, which was Anthropic’s strategy, has a shelf life measured in months, and Anthropic is now saying so publicly. Its post asks governments to test models like GLM-5.3 and its successors, and asks for defenders to get access to strong models too.
That last request is easy to agree with. What I can’t tell from either document is how many real attacks this has already changed. Anthropic’s tests are simulated, run on benchmarks and a sandbox. I didn’t find a sourced case of GLM-5.3 doing damage in the wild, and I’d be wary of anyone who claims one without a source.
For what the US side is doing about its own agents, see Nvidia’s agent safety platform and the FTC’s investigation. Neither touches an open model like this one.
Sources
- Anthropic: GLM-5.3 and the spread of advanced cyber capabilities (September 29, 2026)
- NIST CAISI: CAISI’s Assessment of Z.ai’s GLM-5.3 Cyber Capabilities (September 17, 2026)
- The Next Web: Anthropic says China’s GLM-5.3 nearly matches Mythos at cyber exploits
- South China Morning Post: Anthropic raises alarm over elite hacking ability of Chinese firm Z.ai’s GLM-5.3 (September 30, 2026)