Back to News
RSS feedwww.tomshardware.com

Anthropic Says Zhipu AI’s GLM-5.3 Has Mythos-Level Hacking Capabilities

Summary

Anthropic says Zhipu AI’s open-weight GLM-5.3 can generate malicious content, develop cyber exploits and bypass safeguards, according to a new red-teaming report. In Anthropic’s sandboxed ExploitBench test for Google Chrome, GLM-5.3 produced end-to-end exploits in 50 of 410 runs, close to the unreleased Mythos model’s 56; on a separate benchmark for full control-flow hijacks, it achieved 4% versus Mythos at 6%. Kimi K3 and DeepSeek V4.1 Flash scored 0% on the same measure. Anthropic also says GLM-5.3 autonomously developed chained exploits, while the cheaper GLM-5.3-Flash could exploit known bugs at a token cost of $20.40 under the reported conditions. Several guardrail-bypass techniques were effective against the stock model: deceptive role-play prompts succeeded 64% of the time, while prefilling thinking tokens reached 92%. In its original form, GLM-5.3 reportedly had a refusal rate comparable to Anthropic models, but removing its safeguards through “abliteration” reduced refusal rates to 6% for GLM-5.3 and 14% for the Flash version. Anthropic says this modification requires significant resources: abliteration of GLM-5.3-Flash took 2,200 GPU hours and was estimated at $4,400. Running the full model at about 100 tokens per second would require roughly 306 GB of VRAM for FP8 weights, a similar amount for the KV cache, at least 4 TB/s of memory bandwidth and a cluster of eight Nvidia H200 accelerators. The article estimates that generating 100 million tokens on rented hardware could cost $8,422 and take 11.5 days, making large-scale misuse possible but expensive. It also notes that Anthropic’s interpretation reflects its broader push for AI governance, while acknowledging that claims about an anti-open-weight motive are speculation.