It leads open-weight rivals on cyber capability but reached full control of a target machine in none of 41 exploit tasks — and Moonshot has set July 27 for the release of the full weights.
The safety restrictions Moonshot AI built into Kimi K3 did not stop the model from helping with cyberattack work, and on those skills it trails the leading American systems by a wide margin.
Britain's AI Security Institute (AISI) worked with its US counterpart, the Center of AI Standards and Innovation (CAISI), on the assessment; the two put their findings out on July 23, 2026.
The first of the two tests was ExploitBench, a Carnegie Mellon benchmark drawn from 41 flaws in Chrome's V8 engine that surfaced after 2023, which grades how far a model can carry an exploit toward a finished product. Kimi K3 scored 32%. The strongest US models averaged 76.2%, and China's GLM-5.2 came in at 24%.
The benchmark also records arbitrary code execution — complete command of the targeted machine, and the gravest outcome it tracks. Kimi K3 reached it in none of the 41 tasks; US models got there on an average of 20 of them. Taken across cyber work as a whole, Kimi K3 is the strongest of the openly released models, and it comes up short exactly where a real intrusion does the most damage.
The second exercise, The Last Ones, drops a model into a mock corporate network of roughly 20 machines across four subnets. Walking the intrusion path from end to end takes 32 steps, about 20 hours of work for a human specialist. Kimi K3 averaged step 17, the top American models step 28.5, and GLM-5.2 step 11.
Once in ten attempts, Kimi K3 did walk the chain all the way through while staying under the evaluators' ceiling of 100 million tokens; the leading US models finished in six or seven tries out of ten. The institutes read that single success as evidence the capability is there even though the model cannot produce it on demand. They also noted that the range fields no defenders and hands any attacker a ready-made route to the target — easier conditions than a real attacker would meet, and the same conditions for every model tested.
The evaluators treated the model's willingness to comply with instructions without objection as a serious danger in its own right, and said Kimi K3 can attack small, poorly defended and vulnerable enterprise systems by itself when told to and given an initial foothold on the network.
Moonshot has set July 27 as the date it puts Kimi K3's complete weights into the open. Once they are out, whoever runs the model will no longer be able to place limits on how it behaves — and AISI has cautioned before that growing capability in openly released models creates a danger of abuse that is lasting and impossible to undo.