Anthropic red team: GLM-5.3 hijacks control flow in 4% of trials
A short post on Simon Willison's blog, dated 29 September 2026, quotes a passage from the Anthropic Frontier Red Team's write-up titled "GLM-5.3 and the spread of advanced cyber capabilities".
The team says it evaluated several models on 100 tasks drawn from its internal Binary Exploitation benchmark. The tasks were selected at random. The measure is whether a model develops a full control flow hijack, the kind of exploit that redirects where a program executes next.
The results: GLM-5.3 develops full control flow hijacks in 4% of the trials. Claude Mythos Preview did so in 6%. So GLM-5.3 performs below Claude Mythos Preview on this benchmark.
The team's point is that the gap between those two is not the main story. In its words, a meaningful threshold has clearly been crossed, because earlier models, like Claude Opus 4.6 and GLM-5.2, do not succeed in any of the tasks. The comparison is between a nonzero success rate for the newer models and none at all for the earlier ones.
The post is a pull quote, not the full report. It names only four models (GLM-5.3, Claude Mythos Preview, Claude Opus 4.6 and GLM-5.2), although the team says it evaluated several.
Key facts
- The Anthropic Frontier Red Team evaluated several models on 100 randomly selected tasks from its internal Binary Exploitation benchmark.
- GLM-5.3 develops full control flow hijacks in 4% of trials; Claude Mythos Preview does so in 6%.
- Earlier models, including Claude Opus 4.6 and GLM-5.2, do not succeed in any of the tasks.
- The team concludes that a meaningful threshold has clearly been crossed, even though GLM-5.3 scores below Claude Mythos Preview.
- The passage comes from a write-up titled "GLM-5.3 and the spread of advanced cyber capabilities", quoted on 29 September 2026.
Why it matters
The result marks a step change on one exploit benchmark, from zero to a nonzero success rate. Claude Opus 4.6 and GLM-5.2 succeed in none of the tasks, while GLM-5.3 reaches 4% of trials and Claude Mythos Preview 6%. The Anthropic Frontier Red Team calls this a meaningful threshold that has clearly been crossed. The title of its write-up, "GLM-5.3 and the spread of advanced cyber capabilities", frames the finding around GLM-5.3 reaching this level as well as Claude Mythos Preview.
Who it affects
The passage concerns the models it names: GLM-5.3, Claude Mythos Preview, Claude Opus 4.6 and GLM-5.2. It is a finding about model capability on binary exploitation, so it is most relevant to people who track how well AI models perform on offensive security tasks. The excerpt describes no policy response, mitigation or reaction.
How to use it
There is nothing to install or run. The benchmark is internal to Anthropic. The practical use is as a reference point: on 100 randomly selected Binary Exploitation tasks, full control flow hijacks appeared in 4% of GLM-5.3 trials and 6% of Claude Mythos Preview trials, and in none for Claude Opus 4.6 and GLM-5.2. Anyone who wants the method and the other models tested needs the full write-up, since this passage is only an excerpt.
How solid is it
The claim comes from the Anthropic Frontier Red Team itself, quoted on a personal blog, and the figures are stated plainly: 100 tasks, chosen at random, with 4% and 6% success rates. The excerpt does not say whether the results are peer reviewed or independently reproduced. The benchmark is internal, and its contents and how a control flow hijack is scored are not described here.
Risks and caveats
The rates are small, and the excerpt does not give the number of trials per task, so it is not possible to tell how many individual successes sit behind 4% and 6%. The gap between GLM-5.3 and Claude Mythos Preview is one the team itself notes, and the claim rests on the contrast with the earlier models. Results for the other models evaluated are not given. GLM-5.3's developer and release date are not stated in this excerpt. A pull quote also leaves out whatever context and limits the full write-up sets out.
“Although GLM-5.3 performs below Claude Mythos Preview here, a meaningful threshold has clearly been crossed: earlier models, like Claude Opus 4.6 and GLM-5.2, do not succeed in any of them.”
— Anthropic Frontier Red Team, GLM-5.3 and the spread of advanced cyber capabilities