Cheap AI Hacking Tool Costs Just $20, Report Finds
A researcher spent just $20.40 (USD) to get Zhipu AI's open-weight model GLM-5.3-Flash to chain two known software bugs into a working exploit, Anthropic's Frontier Red Team found. For anyone holding a crypto wallet, phone, or smart glasses, that low price changes the math on who can attack connected devices.
What actually happened
According to Mixed News, Anthropic's Frontier Red Team watched a researcher build a working exploit chain using GLM-5.3-Flash, the smaller version of Zhipu AI's open-weight model family. The chain combined two software flaws that had already been publicly disclosed, not new zero-days. Total spend came to $20.40 (USD), based on Zhipu's own API pricing. The researcher needed only 20 minutes of hands-on work. The model itself ran for 8 hours to finish the job. Anthropic did not name the flaws or the affected systems. The team called this proof that cheap, smaller AI models can now do offensive security work that once needed specialist skill and far more time.
How we got here
Frontier Red Team is Anthropic's internal group that tests AI models for dangerous capabilities. GLM-5.3-Flash is a cut-down, lower-cost variant of Zhipu AI's open-weight model line. Being open-weight means outside researchers can run it directly, which is why this test used Zhipu's public API pricing rather than a subscription fee. Both flaws in the exploit chain were already public knowledge before testing began. Anthropic has not disclosed which software or vulnerabilities were used. This follows a broader pattern of AI labs publishing red-team findings to flag where automated tools are closing the gap with human attackers.
Why this matters for you
For everyday wallet users, this is a reminder that software patches matter, especially on phones, hardware keys, and wearables that hold or sign crypto transactions. If a cheap open model can chain two disclosed bugs, delaying updates becomes riskier. For builders in the bonuz ecosystem and beyond, patching known flaws quickly is now cheaper for attackers to skip, so it must stay cheap and fast for teams to fix. Smart glasses and other always-connected hardware face the same exposure as phones and wallets.
The bigger question
If a $20.40 open-weight model can already turn two public bug reports into a working exploit, how fast must wallet apps, hardware keys, and smart glasses patch known flaws before attack costs drop toward zero? Who checks AI tools like this before they are put to use, and who decides when a model is too capable to release openly?
What to watch
Anthropic has not set a release date for its full study, and Zhipu AI has not responded publicly to the findings, per the report. Watch for whether Anthropic names the two vulnerabilities, and for any statement from Zhipu. Bonuz will keep tracking how this shapes patch practices for wallets and wearable hardware as more details emerge.






