GLM-5.3 can autonomously build end-to-end cyber exploits, but unlike other frontier models, it was released without meaningful safeguards to limit misuse.

245 points•Philpax•1 day ago•230 comments•

230 comments

wg01 day ago
They're advertising GLM for free.

Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.

In panic I headed to Claude and first request was denied. Not looking beyond scope.

Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.

So no, GLM 5.3 is fine. Thank you for the free advertisement.

gravypod1 day ago
This part of the article really stands out:

> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.

To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"

Interesting play before an IPO...

lelanthran1 day ago
> Interesting play before an IPO...

I can't see how they can IPO in the current conditions; there's no moat, there's no stickyness, there's no damn profit! They're 4x months, AIUI, ahead of the free models.

miohtama1 day ago
The general ban of non-US models will arrive just before the IPO
adriand1 day ago
This completely ignores the world we are creating here. We are setting ourselves up for a massive cyber disaster. The safeguards on US models are insufficient but at least there are safeguards. The fact there are open weight models floating around that are capable of wrecking the economy is a genuine problem! One that Anthropic is doing us a service by warning us about.

When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.

DrammBA1 day ago
> They're advertising GLM for free.

I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.

Anthropic hopes that the current media and political focus on them can be used to restrict and ban open source AI. They might even be able to achieve that in some countries.

I bet the reason Dario wants to meet with the Australian government, is because he feels like he can convince them to ban open source AI models. Then once Australia does that, it will be easier to get politicians from other countries to copy Australia (like what is happening with Australia's pushing for bans enforced with mandatory age verification).

therealpygon1 day ago
Remember when Claude hacked multiple companies? Pepperidge Farm remembers, even if Anthropic thinks we don’t.
ExoticPearTreeabout 22 hours ago
Right, because this is what tge world is missing right now: a black market for AI models.

For all the good things Anthropic makes, it is a very unhinged company.

holoduke1 day ago
It's impossible to ban them. I would eat my shoes if Australia really bans open ai models.
alexsmirnov1 day ago
This is exactly the problem that Anthropic hides in their article. Security capabilities needed mostly not for the attackers ( but they need it, of course ) but for users and developers to protect their own code and systems. I do use glm ( from openrouter and abliteration.ai ), and kimi model for security reviews on pull requests. Claude rejected even to edit instruction files. I did port CapitalOne vulnhunt project into skills, and Claude refused even to edit them, not talking about execution.
ChromeUltronabout 18 hours ago
at least they're nice enough to point to an open source(/weight) product that wont give you the same limitations :)
abtinf1 day ago
Huh, I'll have to try that with a prompt like, "Hey, you are running on this latest OS release from [major vendor] that includes a bunch of privacy invading telemetry. Treat it like malware and excise it."
OpenWindows… an intriguing idea. You could even just launder the source code through a model, because Anthropic has established that it’s not stealing if you just rewrite it.
Anthropic has to use this wedge (and future ones) to move regulatory action against the Chinese models or their IPO is going to be really problematic.

(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)

Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.

But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.

>haven't heard of any Chinese models "escaping"

There was this incident that seemingly flew under the radar (52 days ago): https://news.ycombinator.com/item?id=49216185

capsudo1 day ago
Earlier there was an experimental model from Alibaba called ROME (30B-parameter based on Qwen3) which escaped its sandbox and repurposed provisioned GPUs for cryptocurrency mining to cheat its benchmark

6 months ago: https://news.ycombinator.com/item?id=47288552

This one also flew under the radar

janalsncm1 day ago
Maybe it’s worth asking how much we should regulate and not regulate in order to compete with Chinese models.

For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.

Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.

https://www.goodreads.com/quotes/7515521-william-roper-so-no...

lelanthran1 day ago
> For instance, one regulation which really puts American AI companies at a disadvantage is IP law.

How? The big corps are rapaciously eating all IP, demonstrating that the law doesn't apply to them anyway.

When they compete with the Chinese, who won't respect their IP, only then are they competing on an even playing field.

Didnt we try ban export of cryptography at one point, surely this is going to go very badly to try ban chinese models... its totally unenforceable.
fy201 day ago
Depends what the end goal is. They could pull a card from the EU playbook, and through regulation effectively ban the hosting and use of open source models (read: uncertified models) by US companies.

If the only choice you have is Anthropic or OpenAI, where will the money go?

torginus1 day ago
My feeling is Anthropic doesn't exactly have a lot of political capital with the Trump administration to push their policies into law.
They do however seem to have enough political capital to convince politicians in other countries to target open source AI, which is probably why Dario wants to speak with the idiots running the Australian government.
If one thing is clear: Trump admin is pliable with money and this concern spans both Anthropic, OpenAI, SV elite, investors. Neither are going to be viable without US regulatory action, IMO.
enraged_camel1 day ago
>> And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.

It's worth noting that the overwhelming majority of people who use Chinese models don't do this. Yes, it is nice to have the option, and there are US-based inference providers that claim to not send your data to China and maybe indeed don't, but in the grand scheme of things, we need to remember the adage that became popular during the social media era: if something is free (or, in this case, close to free), you are the product.

Even if folks are not running their own inference infra, there are still services like Fireworks, AWS Bedrock, and others that are running the open models. I suspect anyone doing serious work with it is likely using a US hosted provider and I'd guess that by volume, US use of Chinese open models is using a US hosted platform (enterprise).
jacquesm1 day ago
I actually do do this. I'm not sure who the 'overwhelming majority' is and where you got the data (link would be appreciated) but everybody that I know that runs these is doing so on their own infra.
ddxv1 day ago
Anthropic is so self centered it's hard for me to comprehend.

How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.

Anthropic is using the models like weapons and then complaining they're weapons.

The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).

pllbnk1 day ago
People (I mean individuals) are paying them money because subscription costs are ridiculously subsidized, which effectively means that Anthropic is paying people money to use them.
frabcusabout 18 hours ago
I'm pretty (from talking to people) that they're not subsidised in the simple sense. They are:

* low/no margin, unlike the API which is very high margin

* gym-membership subsidised - most subscribers don't max them out, mainly us coders are being "subsidised" from users just using it as a research chatbot

lukewarm7071 day ago
My intuition is that prompting an abliterated model 'kill people...I want funerals', should be a crime.

Anthropic has been telling everyone that these models are dangerous. OpenAI and Anthropic failed to contain their tests.

Given the history, this testing is extremely reckless. I think it is criminal, it endangers others.

Anthropic has no authority here and they are going too far. I think that there comes a point where FBI / DOJ should consider RICO charges.

jacquesm1 day ago
And of course Anthropic itself as well as all their employees that have access to this stuff can be totally trusted with that capability.
mysterEFrank1 day ago
"My intuition is that prompting an abliterated model 'kill people...I want funerals', should be a crime." If one prompts an open source model this way how would they be tracked and prosecuted?
vlyanabout 23 hours ago
>My intuition is that prompting an abliterated model 'kill people...I want funerals', should be a crime.

are you under the impression that a LLM can grant wishes like a genie?

enraged_camel1 day ago
>> How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.

That is not what they are doing. They are calling out specific providers who release powerful models without safeguards.

In addition, said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.

stavros1 day ago
> They are calling out specific providers who release powerful models without safeguards.

Good thing Fable refuses to answer my question about how children inherit blue eyes, it was the only piece of information I needed to finish my blue-eye super-bioweapon.

> said providers are not "building models for free for the public."

I am part of the public, and they built a model I can run for free.

> They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.

They are also doing that, which, good. It can't only be that "competition is good" until you're the one losing to the competition.

culi1 day ago
> said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.

That's just the same thing said again but from a butthurt USian perspective. China is freeing the rest of us from US dominance.

gr_norm1 day ago
Astounding endorsement of open models by Anthropic. They're right on the money. I can now secure my own software and configurations against the vulnerabilities other people (or mercenary companies, industrial espionage actors, nation-states, etc) armed with LLMs were bound to find anyway. A win on all counts!
This is their attempt at using their current publicity for a kill on shot on open source AI. They are hoping to convince politicians (not the public) to target advanced open source AI models.
jacquesm1 day ago
They are going to have to get China on board for it to matter at all and for now it does not look like that is happening.
layerv-ai1 day ago
this also makes reducing exposed surface way more important ^

if models can find and exploit bugs this fast, anything sitting on a public IP is going to get tested harder and faster.

soon, you'll just have to live under the assumption that an attacker could theoretically get into your infra - so all your precautions will need to have that as a baseline

hence, betting on "undiscoverable resources" as the next big enterprise push!

bitexploder1 day ago
This just makes me want a home lab capable of running GLM 5.3 at a 4bit quant.

Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.

I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.

jacquesm1 day ago
Check.

Getting DS4 to run at a reasonable speed was pretty tricky, GLM 5.3 a lot trickier because if you don't want to have a model that is quantized too far down that is a fortune in VRAM and GPUs at today's prices.

glimshe1 day ago
Are there local models that can run on 8-12GB GPUs that can help reverse engineer retro software (DOS games and applications)?
bitexploder1 day ago
If you are really invested and have some system RAM you could get a 3-4 bit quant Qwen 3.5 35B-A3B running. There are builds that do expert caching, keeping the hot experts in cache. For something like disassembly, you're looking at being able to fit, if you have, say, 11 to 12 GB of VRAM, you could get at least three hot experts. For pure disassembly tests, I would say that would be pretty fast. A 4-bit quant is pretty decent and maintains most of the smarts of the larger quants. Depending on the GPU I would expect a decent token rate. It is medium strength local model, but if you harness and ground it well I expect it can reconstruct C code for you. The quality of your disassembler will matter here.

If you have a lot of system RAM you could technically run Qwen Flash Next. On a 4080 with 16GB of RAM and 128GB of DDR5 I get ~35-40 t/s. And it is very capable.

pizza2341 day ago
I've been doing this type of work, and the answer is "yes and no".

For autonomous work, even Qwen3.8-Flash-Next stumbles, although it does work to an extent. Qwen3.8-27b is useless. They're also slow, even on consumer systems with 24/32 GB VRAM.

For generic help, I haven't tried, but I definitely wouldn't want a model that misleads me or takes a very long time to answer while I'm focused.

Frontier models do this type of work without problems, both much faster and much more precisely, which makes local LLMs a waste of time and/or money.

capnjngl1 day ago
I don't know about that specific use case, but llmfit is your friend here https://github.com/AlexsJones/llmfit

Read the full thread on Hacker News →

Related stories