Contents
A release built on the same base model
In mid-August 2026, Z.ai — the Beijing lab formerly operating as Zhipu AI — shipped GLM-5.3, a 743-billion-parameter text model it bills as the most capable open-weights coding model on the market ¹². The flagship claim is less about the number and more about the recipe. Z.ai says GLM-5.3 uses the identical base model as GLM-5.2, with every improvement coming from post-training ². Decrypt quotes the launch post putting it bluntly: “Scaling post-training is all we did for GLM-5.3” ¹. Over the past month it kept scaling its training stack — more environments, more diverse tasks, more compute — rather than building a larger pretrained model ¹. That trade, base-model scaling versus post-training scaling, is central to the release: a prominent open-weights lab betting that frontier coding and agent behavior can be pulled from a frozen base. ¹
Coding gains measured against rivals
On its in-house Z.ai Code Bench, Z.ai reports a 50% coding improvement ². It also reports better token efficiency: 34.5% at “Max” effort versus GLM-5.2’s 23.4%, using about 75,000 output tokens per task against 96,000 ¹. These figures are the vendor’s own. The official documents also record Terminal-Bench 3.0 rising from 4.6 to 28.3, DeepSWE v1.1 from 46.2 to 66.9, and Agents’ Last Exam (CLI) from 23.8 to 28.5; on GDPval-AA v2, covering 44 occupations, it scored 1,769 points ². Against closed frontier models the lead narrows. GLM-5.3 beats Claude Opus 4.8 on token economy, but Claude Fable 5 reaches 39.5% at Max effort on Z.ai Code Bench and remains ahead of GLM-5.3 ¹. On Terminal-Bench 3.0, Fable 5 (33.7) and GPT-5.6 Sol (34.6) outscore GLM-5.3’s 28.3 ¹. On DeepSWE v1.1, open rival Kimi K3 (67.5) and Fable 5 (69.7) both beat its 66.9 ¹. The pattern is consistent: it clears its own predecessor and many open peers, while closed U.S. models still hold the headline coding boards ¹ — Decrypt’s reading, and one consistent with the numbers.
An emergent cybersecurity jump the vendor flagged
The most consequential — and most sensitive — result is in cybersecurity. Z.ai’s documentation describes “emergent cybersecurity capabilities,” with GLM-5.3 scoring 84.5% on CyberGym, slightly above Mythos 5 (83.8%) and GPT-5.6 Sol (83.6%), and ExploitBench climbing from 24.4% to 54.4% ². Decrypt, citing the lab, reports GLM-5.3 flagged 2,436 vulnerabilities across 269 open-source projects, 1,097 of them medium-to-high severity ¹. The word “emergent” is the vendor’s own framing: it says capabilities appeared beyond expectations as the long-horizon training environment expanded, and that the advantage sits mostly at the front of the vulnerability-exploitation chain, with room for improvement in deeper exploitation and full offensive/defensive tasks ². Independent evidence does not yet establish whether those gains generalize beyond the chosen benchmarks, or whether the exploit jump reflects a genuinely frontier-level capability rather than a benchmark artifact. The “emergent jump” should be treated as an attributed claim, not an established fact. ¹²
Staged release and the two-week weight hold
Distribution is deliberately staged. GLM-5.3 is available now to all GLM Coding Plan users — Max, Pro, and Lite — and on ZCode ²³¹. The switch guide shows it can be loaded as a custom model in Claude Code, Codex, and other coding agents via Anthropic-compatible and OpenAI-compatible endpoints, with a 1M context window (a “[1m]” model suffix), up to 128K output tokens, and a “/effort” command to set thinking intensity ³². API access and open weights follow “in stages following rigorous safety evaluations”; the launch post puts the weights at roughly two weeks after release ¹. So the “open-weights” label applies to what is coming, not what is downloadable today ¹. Economics drive the draw. The plan runs on a points quota with off-peak calls at half price, and GLM-5.2’s official API rate was $1.40 in / $4.40 out per million tokens, versus GPT-5.3-Codex at $1.75 / $14 ¹. The sources reviewed here do not state GLM-5.3’s exact per-token price. Separately, Z.ai is on the U.S. Entity List, so American firms cannot export controlled technology to it ¹. Taken together, this release is a major open-weights bet that post-training compute scaling — not larger base models — yields frontier coding and agent capability, paired with a vendor-flagged, unplanned jump in cyber exploitation skills. ¹