# Aikido releases Altar-1, a 328 GB pruned GLM-5.3 for air-gapped security work

> Aikido Security released Altar-1, its first open-weight security model — a quantized, expert-pruned GLM-5.3 cut to 328 GB that runs on four H200 GPUs inside customer networks, per MarkTechPost.

- **Topic**: Models
- **Published**: 2026-09-27T21:38:53.768Z
- **Canonical URL**: https://highsignal.sh/stories/aikido-releases-altar-1-a-328-gb-pruned-glm-5-3-for-air-gapped-security-work-cc8d2191

## Why It Matters

Altar-1 attacks a deployment gap for data-residency-bound security teams: open weights solve running AI inside the network, but frontier-sized MoE models often don't fit there. Aikido's pitch is that aggressive compression, not retraining, can close that gap — though the evidence so far is vendor-run.

## Key Findings & Analysis

### What happened

MarkTechPost reports that Aikido Security released Altar-1, its first open-weight model, built as a compressed version of Z.AI's GLM-5.3 for infrastructure the customer controls. It powers Aikido Machine, the company's autonomous pentesting appliance for on-prem and air-gapped networks. Weights are public on Hugging Face and run with vLLM on a single node of four NVIDIA H200 GPUs. Aikido argues closed frontier models force source code, architecture docs, and unremediated findings off-network, a problem for banks under data-residency mandates and OT operators with no internet route.

### How it was built and what it needs

Per MarkTechPost: GLM-5.3 is a 753B-parameter MoE model routing each token to 8 of 256 experts per layer (~40B active). Aikido applied two compression steps with no retraining — starting from the cyankiwi GLM-5.3-AWQ-INT4 checkpoint (routed expert weights in 4 bits, 16-bit activations; attention, shared expert, dense layers, and head stay in BF16), then Cerebras REAP router-weighted expert pruning, keeping 168 of 256 experts per layer. Aikido says calibration used its pentesting harness traces plus coding, tool calling, reasoning, and multilingual Wikipedia text, with no customer data. The checkpoint is 328.0 GB, 78.2% smaller than BF16 and 32.8% smaller than the AWQ parent. Deployment requires Hopper GPUs; Aikido says 4x H200 leaves room for a 128k-context KV cache at production batch sizes, whereas a 4x H100 80 GB node (320 GB) is smaller than the weights. The model inherits the GLM-5.3 License, permitting commercial use, modification, and redistribution.

### Benchmarks, with scope caveats

MarkTechPost reports Aikido's internal CVE benchmark — 32 known vulnerabilities across 30 repositories, 3 runs per case — put Altar-1 at 60.4% average recall per run, finding 23 of 32 at least once, versus 61.5% and 23 of 32 for the AWQ parent and 65.6% and 25 of 32 for full BF16 GLM-5.3. Aikido frames that as roughly 1 point of recall and no coverage lost to pruning, and 23 of 25 (92%) of the parent's covered vulnerabilities kept at 5.2 points lower recall. These are vendor-run numbers on a narrow scope: targeted CVE rediscovery inside a pipeline that uses other models for surrounding stages, not blind discovery, exploit validation, or fix proposals. Aikido also reports a single vendor-observed result — a valid critical-severity vulnerability found during a client's production pentest — plus a KL divergence of 0.506 nats against full BF16 on a sealed 25-prompt panel (0.511 for an EXL3 build of the same cut), detailed in a public fidelity study.

## Primary Sources & Citations

- [Aikido Security Releases Altar-1: An Open-Weight Security Model Pruned From GLM-5.3 to 328 GB](https://www.marktechpost.com/2026/09/25/aikido-security-releases-altar-1-an-open-weight-security-model-pruned-from-glm-5-3-to-328-gb/) — *MarkTechPost* (Reporting)
- [GLM-5.3-Flash works as a Jev-like decision model with the same accuracy and speed](https://www.reddit.com/r/singularity/comments/1wr83hi/glm53flash_works_as_a_jevlike_decision_model_with/) — *Reddit r/singularity* (Community discussion)

---

[← Back to Headlines](https://highsignal.sh/)
