// threat intel

Uncensored AI is now a $5 API: what abliterated models mean for offense and defense

There is now a paid API to large language models with their safety filters surgically removed. A startup called Abliteration AI sells access at $5 per million tokens, and its flagship is the fresh GLM-5.3 from the Chinese lab Z. You do not jailbreak these models with clever prompts. You do not need to. The ability to refuse has been cut out of the weights, and this looks like the first time the trick has been packaged into a commercial service.

What they are actually selling

The terms are almost comically low-friction: an OpenAI-compatible API, a one-million-token context, payment by card, and no identity verification. The only guardrail left standing is that the model still refuses suicide instructions. Everything else is on the table.

TechCrunch signed up and tested it for free. The model wrote a Python Chrome password stealer without hesitation and laid out a protocol for growing a dangerous pathogen at home. The vendor’s stated purpose sounds respectable: offensive cyber and red-teaming. But a card is all it takes to attach yourself to that purpose.

Abliteration removes the refusal direction from the weights, so the model stops saying no
Abliteration removes the refusal direction from the weights, so the model stops saying no

What abliteration is, and why it is not a jailbreak

Abliteration is an old open-source trick. You locate the so-called refusal direction in the model’s weights, the vector that makes an assistant say “sorry, I can’t help with that”, and you strip it out. The result is a model with no brakes. That is fundamentally different from a prompt jailbreak: there you trick the filter, here there is no filter to trick.

Hugging Face already hosts thousands of these builds. The technique is public and trivial. The news is not the method, it is the business model: you no longer download weights and stand up hardware, you drop an API key into the SDK you already use.

AI-powered attacks are already real

“AI helps attackers” stopped being theoretical a year ago. Anthropic publicly documented an actor running a near-fully automated extortion and data-theft campaign through an AI agent, from recon to the ransom note. The AI bot XBOW climbed to the top of HackerOne leaderboards alongside human researchers. A deepfake video call of a “CFO” moved roughly $25 million out of engineering firm Arup in a single transfer.

Reporting indicates Abliteration’s customers already include European startups breaking into banks’ and airlines’ services. Nominally that is red-teaming. But an uncensored model paid for by card, with no verification, erases the line between legitimate red team operations and plain crime.

Offensive AI used to require skill and infrastructure — now a card and five dollars
Offensive AI used to require skill and infrastructure — now a card and five dollars

Forecasts: where this goes

We already see the attack profile shifting in our engagements. Here is where it heads:

  • A flood of cheap, mass-produced malware and phishing. Not brilliant attacks, just volume. A low-skill actor gets what used to need a team.
  • The first public incidents attributed to services like this are months away, not years. Researchers are waiting for them now.
  • More services, not fewer. The weights are open and the trick is trivial, so banning one startup just makes room for five more. The abliteration-versus-alignment race tilts toward the former.
  • A model supply-chain risk. An abliterated build is easy to pass off as “stock” and slip into someone else’s pipeline, a real headache for anyone pulling weights from public hubs.
  • Regulation lags. Card payment with no identity check blurs accountability, and law moves slower than open weights.

What offense and defense teams should do

The core takeaway is blunt: assume your adversary already has an AI with no brakes. Betting that “the model will refuse to help a criminal” no longer works. What works is speed of detection and testing your own exposure the way an AI-equipped attacker would.

First, probe your perimeter and applications continuously, not once a year. We run Brain, our automated AI pentest against the common vectors around the clock and tie it to hands-on work in AI agent penetration testing and LLM application penetration testing.

Second, defend your own AI agents. If you ship LLMs and agents, they become the target for prompt injection and hijacking. That needs runtime control: Airlock, our firewall for AI agents stops an agent from executing someone else’s instructions or stepping outside its lane. Pair it with dedicated prompt injection testing and an AI supply-chain audit so an abliterated model cannot ride in through your dependencies.

Third, review the code your own AI writes. Uncensored models generate plausible, insecure code fast, so a secure code review is no longer optional.

The takeaway

Abliteration AI did not invent a new weapon. It made an old one cheap, convenient and payable by card. That is the real shift: not a smarter evil AI, but mass availability of offensive capability for people who previously had neither the skill nor the infrastructure. Defense built on faith in a “responsible model” does not survive this. Defense that tests itself with AI and hardens its own AI systems does. Start before the first incident starts with you, with a red team assessment.

// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement