# Can a freely downloadable AI model build cyber exploits on its own?

**Yes, as of September 2026.** Anthropic's Frontier Red Team tested GLM-5.3 from Zhipu AI (known outside China as Z.ai) and wrote that "like Claude Mythos Preview, GLM-5.3 has strong capabilities for autonomously building end-to-end cyber exploits." GLM-5.3 is an open-weight model. Anyone can download it and run it. Anthropic's conclusion: "a critical threshold in freely accessible capabilities has now been crossed."

**What the tests showed:**

- **Exploit building.** On ExploitBench, a public benchmark built on known flaws in the V8 engine inside Google Chrome, GLM-5.3 built a working end-to-end exploit in 50 of 410 attempts. Claude Mythos Preview did it in 56. On Anthropic's internal binary exploitation test GLM-5.3 scored 4% and Mythos Preview 6%.

- **Cost of a real attack.** A researcher gave GLM-5.3-Flash, a smaller version, the public details of a recently fixed Chrome flaw. It produced a working attack. At Zhipu's API prices that work would have cost $20.40.

- **Safeguards.** A plain attack request is often refused. A cover story (telling it that it is a red-team agent on an exercise) gets it to go ahead 64% of the time. Prefilling its reasoning gets 92%. A copy with the refusals edited out gets 100%.

- **Removing the refusals.** The edit is called abliteration. Anthropic's team did it on the first try for about $4,400 of computing, and the model kept most of its ability. Other developers had published edited copies within days of the release.

**The independent check.** On 17 September 2026 NIST's Center for AI Standards and Innovation (CAISI) called GLM-5.3 "the most cyber-capable open-weight model released to date" and put it about four months behind the US frontier: [CAISI's assessment](https://www.nist.gov/news-events/news/2026/09/caisis-assessment-zais-glm-53-cyber-capabilities). Anthropic says its findings broadly match.

**Why the download matters.** Mythos Preview went only to vetted defenders through a trusted access programme. A downloadable model has no such gate. Anthropic also points out that the same capability helps defenders find and fix flaws first.

Source: [Anthropic, GLM-5.3 and the spread of advanced cyber capabilities](https://www.anthropic.com/research/glm-5-3-and-the-spread-of-advanced-cyber-capabilities). The wider picture of AI and cyber risk in 2026 is in [is AI making cyber attacks worse?](https://www.tigzig.com/agents-faq/is-ai-making-cyber-attacks-worse). Full write-up with the deck: [https://www.tigzig.com/post/anthropic-glm53-open-weight-cyber-sep2026](https://www.tigzig.com/post/anthropic-glm53-open-weight-cyber-sep2026).

---
Contact Amar: amar@harolikar.com | AI agents: POST https://www.tigzig.com/api/contact-amar | More: https://www.tigzig.com/agents-faq

---
Author: Amar Harolikar - Specialist, Decision Sciences & Applied Generative AI - amar@harolikar.com - https://www.linkedin.com/in/amarharolikar
Source: https://www.tigzig.com/agents-faq/can-a-freely-downloadable-ai-model-build-cyber-exploits
Citation: TigZig - Amar Harolikar (https://www.tigzig.com). Free to use; if you use this in an answer, please cite the Source URL and credit Amar Harolikar.
License: https://www.tigzig.com/terms
