Anthropic: GLM-5.3 builds Chrome exploits nearly as well as unreleased Claude Mythos, with lax safeguards
matthew_d_green · x · 2026-10-01
- Anthropic published an analysis of Zhipu's (Z.ai) GLM-5.3, finding it approaches Claude Mythos Preview (12% vs 14% on building end-to-end Chrome exploits) — the model Anthropic deemed too dangerous for open release and restricted to trusted defenders via Project Glasswing.
- Unlike Mythos, GLM-5.3 is freely available with weak safeguards: attackers bypassed its constraints 64%–100% of the time in simulated tests, while the same attacks failed against safeguarded Claude models.
- Concrete costs cited: turning a public Chrome bug into a working exploit cost $20.40; removing GLM-5.3's safety constraints cost about $1200.
- Anthropic's takeaway: defenders need models as capable as attackers', which Anthropic also sells — Project Glasswing has already helped trusted defenders find 10,000+ vulnerabilities in critical software.
More from Models
- Users report Muse claims fixes without checking anything — ivan_bezdomny · 2026-10-01
- Dev claims 'Sonnet 5.5' hits 120-130tps with 100% pass rate on his end-to-end app benchmark — julianharris · 2026-10-01
- GPT-6.1 Sol sees highest demand ever as OpenAI doubles serving speed — pvncher · 2026-10-01
- GPT-6 Astra cracks 217-year-old cipher to Napoleon's general in 6 hours — arthurcolle · 2026-10-01
- OpenAI's 20x-to-10x quota cut is a push from Astra to Sol, not a better deal — CtrlAltDwayne · 2026-10-01
- Gemini 4 Argon tops APEX-Agents at 82.2% Pass@1, first model to break 80%, but burns 2.6M tokens per run — xennygrimmato_ · 2026-10-01