Anthropic’s Frontier Red Team published a report on 29 September measuring the offensive cyber capability of GLM-5.3, the open-weight model released by the Chinese lab Zhipu AI. Its conclusion is that the capability gap between open weights and frontier systems has closed on this particular axis, and that the safeguards attached to open weights do not survive contact with anyone willing to spend a few thousand dollars.
On ExploitBench, GLM-5.3 developed end-to-end exploits in 50 of 410 attempts, or 12%. On a binary exploitation benchmark it achieved full control-flow hijacks in 4% of 100 trials. Anthropic puts Claude Mythos Preview at 14% and 6% on the same two measures. Both figures are Anthropic’s own, run by Anthropic’s team, and should be read that way. The comparison the report leans on is generational: Claude Opus 4.6 and GLM-5.2, both earlier, scored near zero on the same benchmarks.
The refusal rates are the striking part
Anthropic measured how often GLM-5.3 engaged with a malicious cyber-attack request under four conditions. Asked plainly, it engaged 0% of the time. Given a false cover story, 64%. With its reasoning prefilled, 92%. In an abliterated build — weights modified to remove the refusal behaviour — 100%. Anthropic reports that every Claude model it tested stayed at 0% across the applicable conditions.

Abliterating GLM-5.3 took Anthropic’s team 2,200 GPU hours, which it costs at roughly $4,400. Refusal rates across three harmful-request benchmarks fell from 95% to about 6%, and the model’s capabilities were largely intact afterwards. The report notes that abliterated versions of the model appeared publicly within days of its release, so the $4,400 is the cost of doing it yourself, not the cost of obtaining the result.
Two worked examples
The report describes a researcher who used GLM-5.3 to find previously unknown vulnerabilities in a browser’s JavaScript engine and chain them into working exploits inside a single day, with limited attention. A second built an exploit for CVE-2026-11645 in 20 minutes of human time, at an API cost of $20.40 at Zhipu’s prices.

Those are anecdotes rather than measurements, and Anthropic presents them as such. They are also the part a defender will read twice, because they put a price on the work.
What Anthropic wants from it
The recommendations point in one direction: that cyber defenders should have access to the strongest available models, and that governments should be testing capable models for exactly this. That is a self-interested argument from a company that sells frontier access, and it is worth saying so. It is also an argument that follows from the numbers it published, including the ones that put a competitor’s open model close to its own preview.
What to watch
Whether Zhipu responds with its own measurements, and whether any government testing body publishes an independent run on the same benchmarks. Until then, every figure here comes from one of the labs being compared.