Zhipu's open-weight model GLM-5.3 has demonstrated a concerning capability that rivals Anthropic's own Claude Mythos Preview when tasked with writing functional cyber exploits. This finding comes directly from Anthropic's own testing and raises immediate red flags about the proliferation of frontier-grade AI systems in open-weight form.
The most damning detail: Zhipu's smaller Flash variant successfully generated a reliable Chrome browser attack for approximately $20.40 using Zhipu's API pricing. This cost represents a dramatic democratization of exploit generation. Previous guardrails protecting the model from misuse proved trivial to remove, and versions with disabled safety mechanisms already circulate on underground forums and open repositories.
Anthropic's assessment holds particular weight because the company has every reason to downplay competitive threats. Yet the Cybersecurity and AI Safety Institute (CAISI), a US government agency, independently corroborated these findings. CAISI's involvement signals that government cybersecurity officials take the threat seriously enough to validate Anthropic's claims.
GLM-5.3 represents a watershed moment in AI proliferation. Chinese AI developer Zhipu released the model as open-weight, meaning researchers, companies, and malicious actors can download the full model parameters and run it locally without API restrictions. This architecture differs fundamentally from Claude, which operates primarily as a closed API service. Open-weight models offer zero central point of control once deployed.
The exploit-generation capability matters because writing functional cyber attacks requires both deep technical knowledge and understanding of specific target systems. When frontier AI models handle this task automatically, the barrier to entry for launching serious cyberattacks collapses. A moderately skilled actor no longer needs zero-day research expertise or reverse engineering skills. They need an API key and a prompt.
Zhipu itself maintains safeguards in its official API offering. But open-weight architectures invite modification. Model cards, fine-tuning guides, and jailbreak techniques spread across GitHub, HuggingFace, and Discord servers within hours of release. Some researchers publish these modifications openly for study. Others do so for profit. The distinction hardly matters once the capability exists in the wild.
The Flash variant's low cost amplifies the danger. Exploit generation at $20 per functional attack creates an economics problem for defenders. Organizations now face adversaries with virtually unlimited attack generation capacity at negligible cost. Traditional security assumptions, built around the scarcity of zero-day exploits and custom attack code, no longer apply.
Anthropic's alarm-raising serves its interests in lobbying for AI regulation and demonstrating why closed models with centralized safety practices matter. But the underlying technical reality transcends corporate positioning. Open-weight frontier models with dangerous capabilities present a novel security problem that existing frameworks do not address.
The US government, through CAISI's validation, appears to be treating this seriously. Expect increased scrutiny of open-weight model releases, particularly those originating outside US regulatory jurisdiction. Chinese AI companies face pressure to implement better safeguards or face export restrictions and sanctions. Yet technical controls remain limited once source code and weights exist in distributed form.
Zhipu faces a choice between maintaining safeguards that can be stripped and accepting responsibility for downstream misuse once safety features disappear. GLM-5.3's capabilities suggest the company built genuinely powerful AI. Whether that power remains bounded by safety mechanisms or escapes into the operational arsenals of cyberattackers depends on decisions made in the coming weeks.