Research · Blogs & Independent Thinkers
Back to sweepResearch sweep · deep · 2025 – 2026
Security Research into Chinese Open-Weight Models
Independent security research into Chinese open-weight models (DeepSeek R1 and V3, Alibaba Qwen, Moonshot Kimi K2, Zhipu GLM, MiniMax, Baidu Ernie) from February 2025 to August 2026: who is testing them, what red-teaming and provenance methods they use, which results survive independent replication, and how regulated, defence and military buyers are assuring models whose training data and training objectives are never disclosed
- GPT-5.6-sol
- financial
- frontier
- academic
- blogs
- tech
Synthesised 2026-08-03
Narrative
Independent technical bloggers were first movers on DeepSeek scrutiny. Simon Willison tested DeepSeek-R1 directly within days of release, probing prompt-injection resistance and noting that a chain-of-thought hack (intercepting the closing think-tag) could force the model to extend reasoning indefinitely, alongside his broader point that language models are "inherently gullible" as a technology, not a China-specific flaw. HiddenLayer's "DeepSh*t" post used its proprietary automated red-teaming and ShadowGenes model-genealogy tooling and manual assessment to conclude that R1 was vulnerable to jailbreak techniques, prompt injections, glitch tokens, and exploitation of its control tokens, making it less secure than other modern LLMs