GLM-5.3-Flash Built a Working Exploit Chain for $20.40

By bonuz NewsroomPublished October 1, 2026
GLM-5.3-Flash Built a Working Exploit Chain for $20.40

Anthropic's Frontier Red Team reports that a researcher used Zhipu AI's open-weight model GLM-5.3-Flash to build a working exploit chain for two already-disclosed software flaws, spending only $20.40 (USD) in API costs. The result shows how cheap automated hacking tools are becoming, a concern for anyone running connected devices, including smart glasses.

What actually happened

According to Anthropic's Frontier Red Team, a researcher built a reliable exploit chain using GLM-5.3-Flash, the smaller version of Zhipu AI's open-weight model. The chain targeted two already-disclosed software vulnerabilities, not new zero-day flaws. The total cost was $20.40 (USD), based on Zhipu's API pricing. The process required 20 minutes of direct human attention. The model itself worked for eight hours to complete the task. Anthropic did not name the specific flaws or the affected systems, according to the report. The team framed this as evidence that smaller, cheaper AI models can now perform complex offensive security work that once required specialist skill and significant time.

How we got here

Frontier Red Team is the part of Anthropic that tests AI models for dangerous capabilities, as the team's own report describes its work. GLM-5.3-Flash is a smaller, cheaper variant of Zhipu AI's open-weight large language model family. Open-weight models let researchers run and test them directly, which is why this test used Zhipu's own API pricing instead of a subscription fee. The two flaws used in the exploit chain had already been made public before the test began, per the report. Anthropic's Frontier Red Team did not specify which software or which vulnerabilities were involved, based on the material currently available.

Why this matters for you

For device makers building AR and smart glasses, this result is a signal. Connected hardware often runs on known software stacks with publicly disclosed flaws. If a cheap, open-weight model can chain those flaws together, attackers no longer need large teams or budgets. Builders should patch disclosed vulnerabilities faster. For everyday users, this means software updates on connected devices, including wearables, matter more than before. For crypto holders, any connected wallet or hardware key faces the same economic shift. Exploits that once required specialist skill may now cost very little to reproduce.

The bigger question

If a cheap, open-weight model can already turn two public vulnerability reports into a working exploit chain, what happens as these models get faster, cheaper, and more capable? Should security teams rethink how quickly disclosed flaws must be patched, especially for connected hardware like AR glasses and wearables, where exploit costs could soon approach zero? And who checks these AI systems before they are used this way?

What to watch

Anthropic's report does not list a public release date for the full study or details on next steps. Zhipu AI has not commented on the findings, based on available material. Watch for responses from either company, and for whether Anthropic names the two vulnerabilities used in the test. Bonuz will track how this affects security practices for connected AR and wearable hardware as more detail becomes available.

Keep reading