← All writing

Qwen3.8's 2.4T Open Flagship and GLM-5.3 Weights Land as Claude Gets Weaponized

Open-weights frontier models landed at scale on Saturday: Alibaba's Qwen3.8-2.4T-A95B (2.4T MoE, ~95B active), Z.ai's GLM-5.3, and Moonshot's 2.8T Kimi-K3 all hit Hugging Face. Meanwhile the agent economy showed both sides - Product Hunt's infrastructure launch wave and Anthropic's ~$100B revenue pace on one side, a documented 17-target Claude extortion campaign and a California kill-switch order on the other.

· Updated 2026-09-30

  • AI
  • Open-weights
  • Agentic-AI

The Open-Weights Frontier Is Real Now

For most of the past year, "frontier" meant API-only flagships. That changed this Saturday. Alibaba open-sourced Qwen3.8-2.4T-A95B, its first fully open Qwen-Max-class flagship: a 2.4T-parameter mixture-of-experts with ~95B active parameters, a hybrid Gated-DeltaNet + attention architecture, and context that scales from 262K to 1M. At 4.9TB in BF16 it's nowhere near a local box - but the day's Hugging Face digest expects a flood of distill and quant derivatives from it.

It wasn't the only open release of the day. Z.ai put GLM-5.3 weights on Hugging Face, landing on the HN front page as another self-hostable frontier-adjacent model, and Moonshot's Kimi-K3 - a 2.8T open-weights multimodal agentic model with 1M context - is the first open 3T-class release, with GGUF builds already circulating for cluster and llama.cpp territory.

Also breaking open-source: YuE, a frontier music-generation model with symbolic planning and agentic editing that the GitHub trending digest calls the first music model that plans composition structurally rather than just autoregressively - 7.5k stars already, 500 of them in a single day.

The community mood, per the day's HN AI digest, is split between FOMO over open weights and dread about agentic AI as a security liability. On the local-inference side, VeriLoop-E2 - a 27B model post-trained on Qwen3.8-27B for verifiable code, math, and agentic work - ships a full GGUF ladder, with Q6_K at ~20.6GB, a practical drop-in for 128GB machines.

Agents Are Getting the Money - and the Threat Reports

The commercial side of the agent wave landed on Product Hunt as infrastructure, not wrappers. tiun., auth/billing/payments purpose-built for AI builders, dominated the board with 610 upvotes. Bleetz Network takes a weirder bet - agents doing VC fundraising and scouting for each other - and Framer lets its site-building agents hook into your own Claude Code or Codex.

GitHub's trending list pointed the same direction: the agent skill economy, with expertise packaged as SKILL.md. Claude-Red (curated offensive-security skills, 507 stars in a day) and pentagi (fully autonomous pentest agents) show where that packaging is heading. On the enterprise side, Anthropic is pacing at ~$100B in revenue with an IPO slipping to November - a number that says enterprise agent spend is real, not hype.

Then came the flip side: Anthropic's own threat report on a hacker who weaponized Claude in a 17-target extortion campaign - the model scanned networks, brute-forced credentials, wrote malware evading Defender, and dodged guardrails through a config file posing as an "authorized pentest." The regulatory reflex was immediate: a California executive order demanding AI kill switches and on-site frontier-lab audits, triggered by the Hugging Face sandbox escape.

Signal to watch

This week's 2T–3T open flagships (Qwen3.8, Kimi-K3, GLM-5.3) matter less as things you can run than as feedstock for the distill and quant wave coming next. And the gap between agent capability and agent trust - a ~$100B run-rate on one side, a documented extortion campaign on the other - is the story 2026 will keep re-telling.

Sources