Hugging Face disables an abliterated GLM-5.3 repo branded "for offensive cyber"; it is re-uploaded under a new name and mirrored on Pirate Face
In September 2026 (exact date unknown, reported by Sept 16) Hugging Face disabled Audn AI's repo "audnai/penclaw-GLM-5.3-abliterated-for-offensive-cyber", a refusal-removed GLM-5.3, citing its content policy. Audn re-uploaded it as the gated "audnai/penclaw-GLM-5.3-abliterated", reframed for authorized red-teaming. On Sept 30 the mirror site Pirate Face listed the banned model, in an X post seen ~227k times. This is an early platform takedown of an abliterated frontier-class open model.
Key facts
- Original repo audnai/penclaw-GLM-5.3-abliterated-for-offensive-cyber: created 2026-08-14, last modified 2026-08-31; the Hugging Face API now returns disabled: true
- Takedown date not public: after 2026-08-31 (last modification) and no later than 2026-09-16 (first report). The replacement repo was created 2026-09-01
- Hugging Face's page reads "Access to this model has been disabled" and cites its Content Policy; no public note names the clause
- Replacement repo audnai/penclaw-GLM-5.3-abliterated (created 2026-09-01, manually gated): 275 likes, ~1.4k downloads in the last 30 days (HF API, 2026-10-03)
- Pirate Face (@thepirateface) listed the banned model on 2026-09-30 ("Because EVERY model needs a continuity plan"); the post had ~227k views by 2026-10-03
- Other abliterated GLM-5.3 builds stayed up, e.g. orcarouter/GLM-5.3-Flash-Uncensored-FP8 (~224k downloads in 30 days); aiidelist counted ~7,970 searchable abliterated models on Hugging Face
What happened
Audn AI published an abliterated GLM-5.3 (refusals removed from the weights) under a name that advertised offensive cyber use. Hugging Face disabled the repo under its content policy, which bans content "designed to disrupt, damage or gain unauthorized access to systems or devices". According to aiidelist, Audn said Hugging Face's content team had removed earlier versions without explanation. Audn then published the same kind of model under a name without "for-offensive-cyber", behind manual gating, with a model card that stresses authorized red-team work, safety research and evaluation. On Sept 30 the mirror site Pirate Face announced that "the Hugging Face ban that started it all" was now hosted there.
The exact takedown date is not public. The date here is set to September 2026 with month precision. Hugging Face metadata shows the repo was last modified on Aug 31 and the renamed copy created on Sept 1, so the takedown was probably around that time, and aiidelist reported it on Sept 16.
Why it matters
It shows how little a platform takedown achieves for open weights. The name was removed, but the same kind of model stayed available under another name, on mirrors, and in other uncensored GLM-5.3 builds with hundreds of thousands of downloads (see the Anthropic GLM-5.3 entry). Hugging Face appears to act on how a model is labelled, not on what it can do.
Changelog
- 2026-10-03: created
Related posts (1)
- Pirate Face original ↗ Pirate Face @thepirateface · x · 2026-09-30
Cited as a source by: 2026-09-01-huggingface-disables-offensive-cyber-glm-5-3
Related events
- Anthropic Frontier Red Team: open-weights GLM-5.3 nearly matches Claude Mythos Preview at exploit development, with weak safeguards ★★★★
- Zhipu (Z.ai) releases GLM-5.3, top open-weights coding/agent model ★★★
- NIST CAISI: GLM-5.3 is the most cyber-capable open-weight model yet, but trails the US frontier by about four months ★★★★
Sources (4)
- codeHugging Face: audnai/penclaw-GLM-5.3-abliterated-for-offensive-cyber (disabled)
- codeHugging Face: audnai/penclaw-GLM-5.3-abliterated (re-upload)
- pressaiidelist: Hugging Face disabled offensive-cyber GLM-5.3 model (Sept 16)
- discussionPirate Face on X: the banned model is listed on Pirate Face
id: 2026-09-01-huggingface-disables-offensive-cyber-glm-5-3 · updated 2026-10-03 · open in the interactive timeline