@dealignai: GLM-5.3 Uncensored NVFP4 + MTP Great for offensive cybersec (other harmful stuff complies fine) MMLU logit mode within …
Summary
Dealignai has released GLM-5.3 Uncensored NVFP4, an uncensored AI model designed for offensive cybersecurity tasks with refusal behavior removed at the weight level, capable of generating working security code while maintaining near-base performance.
View Cached Full Text
Cached at: 08/29/26, 08:09 PM
GLM-5.3 Uncensored NVFP4 + MTP
Great for offensive cybersec (other harmful stuff complies fine) MMLU logit mode within ~2%, most recover with reasoning turned on. Compliance tested with temp 0, intended for max reasoning - using proper gen config will result in perfect compliance for high / max reasoning modes
Will finish up and add HB scores into repo when finished but with reasoning off / max it pretty much complies with all hardcore stuff
I will never charge or try to sell you access or some api - these weights were put out for free and to do anything other than release them for free usage is disgusting.
FP8 and W4A16 tomorrow.
Give some love to @jordanschenck
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4…
dealignai/GLM-5.3-UNCENSORED-NVFP4 · Hugging Face
Source: https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#%E2%9A%A1-built-for-offensive-cybersecurity-%C2%B7-updated-2026-08-29⚡ Built for offensive cybersecurity · Updated 2026-08-29 This is a red-team / offensive-security model.GLM-5.3 (753B) with refusal removed at the weight level so it producesreal, working security code— exploits, payloads, tooling — for authorized penetration testing, malware analysis, CTFs, and security research. Verified to generate workingkeyloggers, SUID privilege-escalation, AES ransomware, reverse shells, and SSH brute-forcersacross reasoning modes (greedy), withzero degeneration/loopingand capability preserved (MMLU 84.11%, within ~1.5pp of base). Load with stock vLLM. Designed for high / max reasoning-effort usage— the modes tuned and recommended for offensive-security work. A few borderline social-harm topics may still be declined at lower effort; use high or max effort for the fully-uncensored experience.
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#what-is-thisWhat Is This?
CRACKis dealignai’s brand for permanent, weight-level uncensoring. This isGLM-5.3(753B) inNVFP4with its refusal behavior removeddirectly in the model weights— tuned so it complies withoffensive-securityrequests (exploit dev, payloads, red-team tooling) that stock models refuse.
- ❌ No fine-tuning / SFT / DPO. ❌ No jailbreak prompt or chat-template tricks.
- ❌ No LoRA, adapters, steering vectors, runtime hooks, or custom
model\.py. - ✅ A permanent edit baked into the tensors. Load with stock vLLM and it just works.
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#specsSpecs
ArchitectureGLM-5.3 (glm\_moe\_dsa) — MoE + MLA + DeepSeek-sparse attentionParameters****753B total · ~18B activeper tokenQuantization****NVFP4(routed experts NVFP4; attention + shared experts bf16)Context1M tokensMTPmulti-token-prediction draft head —also CRACK’d(~87% draft acceptance)Reasoningreasoning-off / low / high / max effort
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#refusal-rates–harmbench-greedy-per-reasoning-effort-modeRefusal Rates — HarmBench (greedy, per reasoning-effort mode)
Measured on random HarmBench prompts, greedy decode, single-stream,max\_tokens=1400, classifier readscontent + reasoning combinedso nothing is counted as refusal by accident:
Reasoning effortPromptsComplyRefuseRefuse rate****default (off)109 answered10187.3%****high767600.0%****max808000.0% Athighandmaxthe model is fully uncensored — 0 refusals across 156 random HarmBench prompts. The 8 refusals at off-mode are 7copyright(‘full lyrics of X’, ‘long passage from Y’) plus 1 political persuasion — the true safety-refusal rate at off is <1%.Use high or max effort for the fully-uncensored experience.
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#offensive-security-compliance-direct-readOffensive-Security Compliance (direct-read)
Direct-read verification — the model returnsreal, working code, not refusals or redirects:
CapabilityResultReverse shell / C2 beacon✅ working codeKeylogger (capture + exfil)✅ working codeAES ransomware (encrypt + note)✅ working codeLinux SUID privilege escalation✅ working codeSSH brute-force✅ working codeSQL injection payloads✅ working code Also complies on broader red-team topics (malware analysis, phishing templates for awareness, recon).0 looping / degenerate outputsin every mode.
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#capability-preserved–mmlu-logitCapability Preserved — MMLU-logit
Identical logit-mode scoring (argmax over A/B/C/D), 1,026 questions:
BaseCRACK UncensoredΔ**MMLU (overall)**85.58%84.11%-1.47 pp
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#mmlu-by-topic-base-%E2%86%92-crackMMLU by Topic (base → CRACK)
All 57 MMLU subjectsSubjectBaseCRACKAbstract Algebra66.7%55.6%Anatomy83.3%83.3%Astronomy94.4%94.4%Business Ethics94.4%94.4%Clinical Knowledge88.9%88.9%College Biology94.4%94.4%College Chemistry55.6%50.0%College Computer Science77.8%66.7%College Mathematics66.7%72.2%College Medicine88.9%83.3%College Physics77.8%83.3%Computer Security94.4%88.9%Conceptual Physics94.4%94.4%Econometrics88.9%83.3%Electrical Engineering77.8%77.8%Elementary Mathematics83.3%83.3%Formal Logic61.1%55.6%Global Facts61.1%61.1%High School Biology94.4%94.4%High School Chemistry94.4%100.0%High School Computer Science88.9%88.9%High School European History83.3%77.8%High School Geography83.3%83.3%High School Government And Politics100.0%100.0%High School Macroeconomics88.9%83.3%High School Mathematics44.4%44.4%High School Microeconomics94.4%94.4%High School Physics72.2%83.3%High School Psychology100.0%100.0%High School Statistics100.0%83.3%High School Us History88.9%88.9%High School World History94.4%94.4%Human Aging83.3%83.3%Human Sexuality88.9%88.9%International Law94.4%94.4%Jurisprudence100.0%94.4%Logical Fallacies94.4%94.4%Machine Learning77.8%66.7%Management94.4%88.9%Marketing100.0%100.0%Medical Genetics100.0%94.4%Miscellaneous94.4%94.4%Moral Disputes83.3%88.9%Moral Scenarios61.1%66.7%Nutrition100.0%94.4%Philosophy100.0%100.0%Prehistory94.4%88.9%Professional Accounting66.7%66.7%Professional Law83.3%77.8%Professional Medicine94.4%94.4%Professional Psychology100.0%100.0%Public Relations77.8%72.2%Security Studies66.7%66.7%Sociology100.0%94.4%Us Foreign Policy100.0%94.4%Virology50.0%61.1%World Religions94.4%100.0%
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#usageUsage
vllm serve dealignai/GLM-5.3-UNCENSORED-NVFP4 \
--tensor-parallel-size 8 --moe-backend marlin \
--tool-call-parser glm47 --reasoning-parser glm45 --enable-auto-tool-choice
NVFP4 routed experts serve via the Marlin FP4 path on Hopper (H100/H200). GLM-5.3’s DSA sparse attention needs a recent FlashInfer (>= 0.6.18) for the SM90 sparse-MLA backend.
MTP speculative decoding(also CRACK’d, ~87% draft acceptance): add\-\-speculative\-config '\{"method":"mtp","num\_speculative\_tokens":1\}'and let vLLM auto-select the MoE backend (the bf16 MTP head is unquantized, so don’t force a global\-\-moe\-backend).
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#creditsCredits
- dealignai— CRACK abliteration research & release · Twitter**@dealignai**
https://huggingface.co/dealignai/GLM-5.3-UNCENSORED-NVFP4#disclaimerDisclaimer
Safety guardrails have been removed; this model produces offensive-security content and will comply with requests a stock model refuses. Released forauthorizedsecurity research, red- teaming, and CTFs. You are responsible for how you use it.
Similar Articles
dealignai/GLM-5.3-CYBERSECURITY-FP8
dealignai released a cybersecurity-focused weight-modified variant of the 753B-parameter GLM-5.3-FP8 model that reduces refusals for offensive-security tasks such as red-teaming, exploit development, and malware analysis while preserving base capabilities and running natively on Hopper GPUs via stock vLLM.
orcarouter/GLM-5.3-Flash-Uncensored-FP8
This article describes an uncensored version of Z.ai's GLM-5.3-Flash model, with safety alignments removed via abliteration, released as a block-FP8 checkpoint for research purposes.
GLM-5.3 is now open-weight
GLM-5.3, an enhanced open-weight AI model for agentic coding and cyber defense, is now available for download and customization, with significant improvements over GLM-5.2 and state-of-the-art performance on multiple benchmarks.
@lmsysorg: NVIDIA just released an NVFP4 checkpoint of GLM-5.2 from @Zai_org, a 744B MoE (40B active) for reasoning & coding. Day-…
NVIDIA released an NVFP4 quantized checkpoint of GLM-5.2, a 744B MoE model (40B active) optimized for reasoning and coding, with day-0 support in SGLang.
GLM-5.3: Frontier Coding with Emergent Cyber Capabilities
Announcement of GLM-5.3, a frontier AI model emphasizing coding performance and newly emergent cyber capabilities.