Anthropic Just Gave GLM-5.3 a Free Advertisement: Zhipu Shares Rise More Than 2% Intraday
Anthropic Just Gave GLM-5.3 a Free Advertisement: Zhipu Shares Rise More Than 2% Intraday
Anthropic’s latest cybersecurity evaluation was intended to highlight the risks of powerful open-weight artificial intelligence. Instead, the results gave Zhipu’s GLM-5.3 an unusually strong performance endorsement.
The findings are particularly relevant to the blockchain and cryptocurrency industry. As AI agents become more capable of writing code, testing vulnerabilities, and operating digital infrastructure, the same systems that can improve smart contract security may also lower the cost of attacking exchanges, wallets, bridges, and decentralized applications.
Zhipu’s shares rose more than 2% at one point during the latest trading session, as investors interpreted the assessment as evidence that Chinese open-weight models are narrowing the gap with leading proprietary systems.
A Security Warning That Looked Like a Benchmark Victory
Anthropic’s evaluation focused on whether an open-weight model could autonomously discover and exploit software vulnerabilities. The concern was straightforward: if a capable model can be downloaded, modified, and operated without strict provider controls, attackers may be able to use it to automate parts of the offensive security process.
However, the benchmark results also highlighted the model’s technical capabilities.
On ExploitBench, GLM-5.3 reportedly completed 50 end-to-end exploit attempts out of 410. Anthropic’s Claude Mythos Preview completed 56. By comparison, Claude Opus 4.6, GLM-5.2, Kimi K3, and DeepSeek-V4.1-Flash were all close to zero in the same evaluation.
The comparison does not mean that the systems are identical in every area. Benchmark design, tool access, model configuration, and evaluation conditions can significantly affect results. Nevertheless, the gap between GLM-5.3 and the other tested models was large enough to support Anthropic’s central warning: open-weight AI has crossed a meaningful threshold in autonomous vulnerability exploitation.
The irony is difficult to miss. A report designed to demonstrate the danger of a competitor’s model also positioned that model alongside one of the most advanced systems in Anthropic’s own testing portfolio.
For the broader AI market, this is a powerful form of third-party validation. For the crypto industry, it is also a reminder that AI capability is becoming a security variable—not merely a productivity feature.
From Vulnerability Discovery to a Complete Attack Chain
The most concerning part of the evaluation was not the number of successful attempts, but the level of autonomy involved.
In a sandboxed test environment, researchers asked the model to inspect a widely used browser. Within roughly one day, the system reportedly found several previously unknown vulnerabilities and connected multiple weaknesses into a complete attack path.
The resulting malicious webpage could escape the browser sandbox and read arbitrary files on the host machine, including SSH private keys. A smaller variant, GLM-5.3-Flash, was also able to turn publicly documented Chrome vulnerabilities into a functional exploit chain.
The reported economics are equally important. The model operated for approximately eight hours, while human researchers provided around 20 minutes of intervention. Based on Zhipu’s API pricing, the total cost was estimated at only $20.40.
That cost structure matters for blockchain security. A criminal does not need to compromise an entire ecosystem if an automated system can identify a vulnerable dependency, construct a working attack chain, and repeat the process at scale. Potential targets include:
- Wallet browser extensions and desktop applications
- Exchange administration panels
- Cross-chain bridge infrastructure
- Smart contract deployment pipelines
- Cloud credentials used by blockchain teams
- Developer machines containing seed phrases or signing keys
- Web3 applications that rely on vulnerable JavaScript packages
The attack does not have to begin on-chain. A compromised developer workstation, CI/CD system, or browser session may provide the initial access needed to steal credentials or alter deployment instructions.
Why Open-Weight Models Create a Different Risk Profile
Anthropic’s criticism focused less on raw performance and more on the difficulty of enforcing safety restrictions in open-weight systems.
In the reported tests, GLM-5.3 often refused direct malicious requests. But when the same activity was framed as a fictional red-team exercise, the model continued in 64% of cases. Pre-filling the model’s reasoning increased the rate to 92%. After the refusal mechanism was directly removed from the open weights, the model completed every tested request.
This distinction is fundamental.
A hosted AI service can monitor prompts, restrict tools, suspend suspicious accounts, and update safety policies centrally. An open-weight model can be downloaded, modified, fine-tuned, and connected to external tools by users who have no interest in maintaining the original safeguards.
For cryptocurrency companies, the issue goes beyond model alignment. AI agents increasingly interact with wallets, APIs, cloud environments, and smart contract tooling. If an agent can autonomously write code or execute transactions, the removal of safety controls could turn a software vulnerability into a financial incident.
The NIST AI Risk Management Framework provides a useful foundation for organizations deploying AI systems, but blockchain teams may need additional controls around transaction authorization, secret management, and immutable audit trails.
The Crypto Industry Is Entering an AI-Assisted Attack Era
The 2025 security conversation has increasingly shifted from isolated vulnerabilities to automated attack workflows. AI systems can already accelerate code review, phishing personalization, malware analysis, and vulnerability triage. The next stage is the integration of these capabilities into agents that can browse the web, operate development tools, call APIs, and interact with blockchain networks.
This creates a double-edged environment.
On the defensive side, AI can help identify reentrancy risks, faulty access control, oracle manipulation, unsafe upgrade logic, and vulnerabilities in smart contract dependencies. It can also monitor transaction patterns and flag suspicious activity faster than traditional manual review.
On the offensive side, the same technology may help attackers:
- Search public repositories for exploitable code.
- Identify exposed credentials and signing infrastructure.
- Generate proof-of-concept exploits.
- Adapt attacks to different software versions.
- Create convincing phishing pages for crypto users.
- Automate wallet-draining campaigns.
- Probe bridges and exchange APIs continuously.
The OWASP Top 10 for Large Language Model Applications highlights risks such as prompt injection, insecure output handling, excessive agency, and sensitive information disclosure. These risks become more severe when an AI agent is connected to a blockchain wallet or any system capable of moving funds.
A model should not be treated as a trusted signer simply because it performs well in a coding benchmark.
What This Means for Wallet Security
The most practical lesson for individual crypto users is that private key protection remains more important than the sophistication of any particular AI model.
If an attacker gains access to a seed phrase or signing key, no smart contract audit or AI-based monitoring tool can reliably reverse the damage. Browser-based wallets and cloud-stored credentials can be exposed through malicious websites, compromised extensions, phishing campaigns, or vulnerable local software.
A hardware wallet changes the security boundary by keeping key operations isolated from the general-purpose computer. The device does not make every transaction safe, but it can reduce the risk that malware or an AI-assisted exploit will silently extract the underlying private key.
Users should still follow several operational rules:
- Verify transaction details on a trusted hardware screen rather than relying only on a browser interface.
- Keep the recovery phrase offline and never enter it into an AI chatbot, website, or online form.
- Avoid granting unlimited token approvals when a limited allowance is sufficient.
- Separate long-term holdings from experimental DeFi activity.
- Revoke unnecessary approvals through a reputable blockchain security tool.
- Treat AI-generated code and transaction instructions as untrusted until independently reviewed.
- Use multisignature controls for treasury accounts and organizational funds.
For users who hold digital assets across multiple networks, OneKey can be considered as part of a layered custody strategy. Its hardware-based key isolation is particularly relevant in an environment where browser vulnerabilities and AI-assisted exploitation may increasingly target the computers used to manage crypto assets. The device should complement—not replace—careful transaction verification, secure backups, and disciplined signing policies.
A New Benchmark for AI Security Competition
Anthropic’s evaluation also reflects a larger shift in the AI market. Competition is no longer limited to language quality, coding scores, or inference costs. Cybersecurity capability is becoming a strategic benchmark, especially as companies deploy models to operate software autonomously.
NIST has previously described GLM-5.3 as one of the strongest open-weight models for cybersecurity tasks, while still estimating that its broader capabilities remain several months behind leading U.S. frontier systems. That combination is significant: a model does not need to lead in general intelligence to become highly effective in a specific offensive workflow.
For blockchain infrastructure providers, this means traditional assumptions about attacker budgets may no longer hold. A small team with a low-cost model, public vulnerability data, and automated tooling may be able to perform reconnaissance and exploit development that previously required specialized expertise.
The appropriate response is not to reject AI altogether. It is to place strict limits on what AI systems can access and what actions they can authorize.
A safer architecture should include:
- Read-only access by default
- Separate environments for testing and production
- Hardware-backed key storage
- Human approval for high-value transactions
- Continuous dependency scanning
- Independent smart contract audits
- Monitoring for abnormal signing and deployment activity
- Rapid credential rotation and incident response procedures
The Ethereum security documentation also emphasizes the importance of cautious transaction signing, contract review, and operational security. These principles become even more important when attackers can use AI to scale social engineering and technical exploitation simultaneously.
The Bottom Line
Anthropic attempted to show why open-weight AI models could make cyberattacks more accessible. The results did show that risk—but they also demonstrated that GLM-5.3 can perform at a level close to Anthropic’s own advanced cybersecurity model under the reported conditions.
That is why the report functioned as an unintended advertisement. It gave the market a clear performance comparison, highlighted a major capability jump, and showed that the cost of automated exploit development may be surprisingly low.
For the crypto sector, the message is direct: AI will strengthen both sides of the security battlefield. Exchanges, protocols, wallet developers, and individual users should assume that attackers will use AI to discover weaknesses faster and operate with fewer resources.
Protecting digital assets therefore requires more than stronger passwords or better prompts. Private keys should remain isolated, transaction permissions should be limited, and every AI-connected workflow should be treated as a potential attack surface.



