← Back to the wire

Can an Open Model Do Security Research? Cantina's apex-flash-1 Solves 40 of 60 Held-Out Bug Tasks

AchievementModelOct 5, 2026

Cantina Security and Yeta Labs released apex-flash-1, an open-weights vulnerability research model built as a GRPO fine-tune of Z.ai's GLM-5.3-Flash, available on Hugging Face under the MIT license. On Cantina's internal 60-task benchmark, it solved 40 tasks (66.7%) for about $2.38, while Claude Opus 5 High solved 43 (71.7%) for about $74.68. The 321.3B-parameter model requires roughly 640 GB of GPU memory in BF16.

Receipt № 22251 source · awaiting confirmation ◐

Evidence

1source· awaiting independent confirmation

No score is assigned. Sources and their independence are shown in the citation chain below.

Citation chain · 1 source

Hugging FaceCompanyZ.aiCompanyGLM-5.3-FlashModelCantina SecurityCompanyYeta LabsCompanyapex-flash-1ModelClaude Opus 5 HighModel
Canonical: https://www.marktechpost.com/2026/10/04/can-an-open-model-do-security-research-cantinas-apex-flash-1-solves-40-of-60-held-out-bug-tasks/