Anthropic report says Zhipu's GLM-5.3 nears its unreleased Mythos in exploit-writing tests
Anthropic published benchmark results claiming Zhipu AI's open-weight GLM-5.3 model can autonomously generate working cyberattack exploits, including chained exploits, with safeguards that can reportedly be bypassed. In its Exploitbench tests, GLM-5.3 produced 50 successful Chrome exploits out of 410 attempts, close to the 56 achieved by Anthropic's own unreleased Claude Mythos model, while rivals Kimi K3 and DeepSeek V4.1 Flash scored 0% on a related control-flow hijack test.
GoKawiil's interpretation of the reporting above, not reported fact.
Anthropic frames the findings as evidence that powerful offensive AI capabilities are spreading into open-weight models it doesn't control, which could complicate its own calls for industry-wide safety pacing and regulation. The comparison to Anthropic's own Mythos model, and its own rapid release of Claude Opus 5.5 and Sonnet 5.5 shortly after raising alarms, may invite scrutiny of whether Anthropic is applying consistent standards to itself versus competitors. As Anthropic pursues an IPO, highlighting risks in a rival Chinese model could also serve to bolster its own safety-focused market positioning, though the report does not state that as its motive.
- Anthropic says Zhipu AI's GLM-5.3 nearly matches its own unreleased Mythos model in autonomous exploit-generation benchmarks.
- GLM-5.3 scored 50/410 successful Chrome exploits versus Mythos' 56/410, while DeepSeek V4.1 Flash and Kimi K3 scored 0% on a related test.
- The report arrives as Anthropic pushes for AI governance while pursuing an IPO and continuing to release new Claude models.
Source: tomshardware.com — Sayem Ahmed, 2026-09-30
Published there as: “Anthropic claims popular Chinese AI model has Mythos-class hacking abilities”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.