AI Built a Working Exploit Chain for $20.40, Anthropic Says

By bonuz NewsroomPublished October 1, 2026
AI Built a Working Exploit Chain for $20.40, Anthropic Says

Anthropic's security team says a cheaper, openly available AI model built a working hack for 2 already known software bugs in under a day, for $20.40. That price shows how affordable real cyberattacks have become for anyone with access to the model.

What actually happened

According to Anthropic's Frontier Red Team, a researcher used GLM-5.3-Flash, the smaller open-weight model from China's Zhipu AI, to build a reliable exploit chain for 2 flaws that were already public. The work cost $20.40 at Zhipu's API prices. It took 20 minutes of human attention and 8 hours of model work, the team's report said. Separately, Florida's attorney general asked a state judge to stop OpenAI from offering ChatGPT to minors in Florida while his lawsuit against the company proceeds. That request is 1 of 6 prohibitions listed in a 49-page motion for a temporary injunction, e-filed on 28 September. No court has ruled on any of the 6 requests yet.

How we got here

Exploit chains usually take trained specialists days of manual work. Anthropic's test shows that gap closing. The 2 flaws used were already public, meaning patches existed, yet a cheap model still turned them into a working attack. Florida's motion is not a new lawsuit. It is a request inside a case the state's attorney general already filed against OpenAI, asking a judge to pause minors' access before the case is decided. Neither story ends in a finished rule. Both show institutions trying to catch something that is already moving.

Why this matters for you

For anyone running software, a known bug is no longer safe just because a patch exists somewhere. Cheap AI tooling means attackers can act before most people update anything. For builders, the lesson is to patch fast and assume someone is already testing the old flaw. For parents and teenagers in Florida, nothing changes yet. The motion is a request, not a ruling, so ChatGPT access for minors in the state stays the same until a judge decides. Anyone relying on AI products for a child should expect more fights like this, in more states, before the rules settle.

The bigger question

Software security has long assumed that patching a known bug buys time before anyone exploits it. If an openly available model can turn 2 already disclosed flaws into a working attack for $20.40, how much of that assumption still holds, and who should close the gap once the price of an attack falls this low for almost anyone with internet access?

What to watch

No court date has been set for Florida's injunction motion. The request still awaits a ruling. Anthropic's report does not say whether it will test the same exploit chain against larger models or other vendors. Readers tracking how fast known bugs become real attacks should watch for Anthropic's next Frontier Red Team update, and for the judge's decision in Florida's case, whichever comes first.

Keep reading