Zhipu AI’s open-weight GLM-5.3 has approached the exploit-building performance of Anthropic’s restricted Claude Mythos Preview, according to tests published by Anthropic and supported by a US government assessment. That combination of capability and downloadable weights raises a practical concern: software safeguards can be removed after release.

On ExploitBench, GLM-5.3 produced a working exploit in 50 of 410 attempts, compared with 56 for Mythos Preview. On Anthropic’s separate benchmark using open-source projects from OSS-Fuzz, it took control of the target program in 4 percent of tasks versus 6 percent for Mythos. CAISI independently described GLM-5.3 as the most cyber-capable open-weight model it had tested, about four months behind leading US systems under its comparison conditions.

Anthropic also reported that the smaller Flash variant combined two browser vulnerabilities into a reliable attack with 20 minutes of human attention and eight hours of model time, costing $20.40 at listed API prices. The vulnerabilities were reported to the developer.

The source has incentives to emphasize risks because Anthropic sells closed models and controlled cyber access. Its simulations also do not prove every generated attack would work. Still, removable refusal behavior and CAISI’s separate capability results make the underlying defensive challenge harder to dismiss.