According to former Anthropic employee Noah Lebovic, black-hat hackers currently rely primarily on Claude Code and Codex rather than open-source models. Lebovic noted that attackers often purchase discounted subscription tokens from gray markets and switch accounts when blocked, as closed-source models offer stronger capabilities at lower subscription costs, with security restrictions serving as merely another hurdle to bypass.
In contrast, legitimate security teams depend more on open-source models like GLM 5.2 because they cannot conduct unauthorized jailbreaks or continuously change accounts. Real vulnerability details and exploit code are prone to triggering filters in closed-source models, according to Lebovic.