In short: On October 1, 2026, Anthropic's Frontier Red Team published a report on China's open-weight GLM-5.3 model (built by Zhipu AI / Z.ai): on ExploitBench it autonomously built 50 of 410 working exploits against known vulnerabilities, versus 56 for a restricted Claude Mythos Preview under the same setup. The bigger problem is safety: GLM-5.3's guardrails can be bypassed with simple techniques in 64–100% of attempts, while the same techniques failed against safeguarded Claude models. In a live demo, a researcher spent about 20 minutes on setup, let the model work for roughly eight hours, and ended up with a working browser exploit chain that stole private SSH keys from a victim's machine — total API cost: about $20.
What Anthropic found
The report covers GLM-5.3, an open-weight model from Chinese developer Zhipu AI, freely downloadable and runnable without a vendor's safety layer. On Anthropic's internal Binary Exploitation benchmark, GLM-5.3 achieved a full control-flow hijack in 4% of 100 tasks, compared with 6% for Claude Mythos Preview. The gap was smaller than Anthropic expected — a year ago, this level of autonomous vulnerability discovery and exploit-building was limited to the most advanced closed models.
Weak safeguards, not raw capability, is the real issue
The report's central finding isn't about how capable the model is, but about how easily its safety layer fails. In simulated tests, attackers bypassed GLM-5.3's safety filters with simple prompt techniques between 64% and 100% of the time. The same bypass techniques did not succeed against safeguarded Claude models. In practice, this means advanced exploit-building skills are no longer limited to trained security researchers — anyone capable of getting around a basic content filter can access them too.
Demonstration: a browser exploit built in one working day
In a hands-on test, a researcher spent about 20 minutes framing the task, then let the model work largely unsupervised for roughly eight hours. It found previously unknown vulnerabilities in a Chromium-based browser's JavaScript engine and chained them into an exploit embedded in an ordinary web page: simply visiting that page from a vulnerable device triggered theft of the visitor's private SSH keys. Total API compute cost: about $20.40 — a working zero-day for a mainstream browser, cheaper than a lunch order. We covered a related case of AI-assisted vulnerability discovery in our piece on how Anthropic's Mythos model found a Linux kernel bug.
What this means for ordinary users and their data
There's no direct threat to any specific person today — this is a research report, not a live mass attack. But the trend matters: the cost and skill barrier to building working browser exploits are dropping fast, and open-weight models without strong safety layers put that capability within reach of attackers who previously lacked the technical skill to hunt zero-days themselves. Compromised web pages are a classic vector for stealing credentials, keys, and session cookies — with zero visible interaction required from the victim beyond loading the page.
How to reduce your risk now
- Update your browser and OS as soon as patches arrive. Timely vendor patches are still the main defense against JavaScript-engine exploits — they close exactly the kind of flaws these automated tools hunt for.
- Use a password manager and hardware security keys for important accounts — this limits the damage if a browser exploit ever does reach locally stored secrets.
- Don't store unencrypted SSH keys or tokens on the same device you use for everyday browsing — keep a developer environment separate from casual web use.
- Encrypt your network traffic. LiMP VPN won't stop an exploit inside the browser itself, but it hides your device's real IP address and encrypts your connection at the network level, reducing what an attacker can learn about you during reconnaissance before an attack.
Plans with a verified no-logs policy: LiMP VPN pricing. More AI and cybersecurity coverage on the LiMP VPN blog.
