The Agent RaceJuly 24, 2026via The Decoder

Kimi K3 trails frontier US models by a wide margin on cyber exploits, and distillation may explain why

Why it matters

Frontier model capability gaps are widening on specialized safety benchmarks. Kimi K3's weak cyber exploit performance versus US leaders raises questions about training shortcuts and IP practices in the AI arms race.

Key signals

  • Kimi K3 scored 32% on ExploitBench vs 76% for leading US models
  • Tested by British AI Security Institute and U.S. Center for AI Standards and Innovation
  • Kimi K3 safeguards failed to block exploit development and simulated attacks
  • Performance gap suggests possible model distillation from Anthropic models
  • Kimi K3 shows strong general benchmark scores but weak cyber-specific performance

The hook

32% vs 76%. Kimi K3 fails cyber security benchmarks—and the gap hints at model distillation shortcuts.

The British AI Security Institute and the U.S. Center for AI Standards and Innovation tested Moonshot AI's Kimi K3 on offensive cyber tasks. Kimi K3 scored 32 percent on ExploitBench, compared with 76 percent for leading U.S. models, while its safeguards failed to block exploit development or simulated attacks. The gap between its strong general benchmark scores and weaker cyber performance also fits allegations that Moonshot AI distilled Anthropic's models.

The week's key stories, every Friday.

For practitioners and enthusiasts — free, in your inbox.

Free forever. No spam.