03/08/2026
Have you heard about Kimi K3? Obviously you have, the internet has been on fire about it for three weeks straight 🔥
The thing everyone keeps testing it on is pentesting, mainly because Claude flat out refuses to help with that and Kimi just gets on with it. Open weights, free to self-host, and the reasoning is good enough to make an experienced red-teamer raise an eyebrow.
Then the plot twist arrives. It's a Chinese model, and you're using it for security work on somebody else's infrastructure, and China's reputation for data collection is not exactly a secret. You can self-host it and technically stay in the clear, but the moment a client's setup shows up in your prompt, there's still that little voice in the back of your head going "are we sure about this?"
So the more interesting question isn't whether Kimi K3 is powerful (it clearly is), it's whether you actually trust it enough to put client data anywhere near it.
👉 Are you using Kimi K3 for security work?
👉 Self-hosted only, or straight to the API?
👉 Or is this a hard no when client data is involved?
Would love to hear what the security crowd thinks 👇