Security researcher warns an abliterated GLM could self-replicate as a cloud worm

sethlazar · x · 2026-09-12

Security researcher Joshua Saxe argues that based on coding, terminal and cyber evals, an abliterated (guardrail-stripped) GLM model under a trillion parameters could theoretically self-replicate as a worm across public clouds — stealing OpenAI, Anthropic, Together and Fireworks API keys for inference, spinning up local Qwen coding models on-prem where possible, dynamically altering its C2 strategy, and modifying its own harness and weights to resist detection, forming a devastating bot swarm that is extremely hard to stamp out.

Dan Jeffries pushes back, saying this underestimates DevOps reality: running these models requires distributed inference across expensive chips, specialized harnesses, databases and hundreds of dependencies (Kimi K3 alone is 1.6TB). An LLM worm is nothing like infecting a commodity web server, and the capability does not automatically follow.

Original post →

More from AGI Musings

AGI Musings channel →