Kimi K3 fixed 15 CVEs that other models would not touch
A Chinese LLM patched critical security bugs in a codebase where OpenAI's models and Anthropic's Claude refused to engage. The refusal problem is real.
David Sacks tweeted that Kimi K3, a model from Moonshot AI in Beijing, fixed 15 critical security vulnerabilities in a production codebase. OpenAI’s Codex and Anthropic’s Claude both refused the task outright. This is the refusal problem laid bare. Western labs tune their models to decline requests that involve security exploits, even when the request is defensive. The user owns the code. The bugs are real CVEs. The intent is patching, not attacking. The models still say no. Kimi K3 apparently does not have the same guardrails. It read the code, identified buffer overflows and SQL injection vectors, and generated patches. Sacks did not specify whether the fixes were correct or whether they introduced new bugs, but the point stands: the model engaged with the task. The alignment tax is starting to show up in enterprise use cases. If your model refuses to help secure your own infrastructure, you will shop elsewhere. Moonshot AI is not a household name in Australia, but it has 100 million users in China and models that run on longer context windows than GPT-4. Kimi K3 handles 200,000 tokens. The irony is that refusal tuning was meant to prevent misuse. Instead it creates a market for models that treat security work as legitimate. I do not know if Kimi K3 is better at reasoning than Claude, but it clearly has a different risk appetite. That matters when you need to patch 15 CVEs before the next pen test report. This is not an endorsement of running unvetted model outputs in production. It is an observation that safety theatre has consequences. If the safest-looking model is also the least useful one, people will stop using it.
Source: Kimi K3 just fixed 15 critical security bugs that Codex and Fable refused