BLOG · 2026-08-01

刺刀见红的模型搏杀 II

Luna降价和DS V4 Flash正式版发布在一天,展现了直接的模型价格战…这背后意味着什么呢?带着这个问题,我查找了些资料。结果,发现其实这半个多月发生了很多…
7月16日 Kimi K3发布,人类历史上第一个开源的三万亿级模型。
7月22日 OpenAI罕见自曝:测试中的模型逃逸后,利用零日漏洞攻击了Hugging Face,而目的只是在评测里作弊。而所有闭源模型在攻击中拒绝读取攻击日志,反而是开原模型GLM5.2帮助下阻止了攻击。
7月24日晚 黄仁勋发出他人生中第一条X,附上联名信《开源模型与美国AI领导力》:25家公司呼吁华盛顿不要限制开源AI模型。OpenAI、Anthropic、Google都不在名单上。但第二天,OpenAI悄悄把名字加了上去;名单翻倍到50家,Google、AMD也来了。
7月27日 Kimi K3如期开源。
7月28日 37家公司成立开放安全AI联盟,主张用开源工具做AI安全防御。OpenAI、Google、Anthropic又都不在。
7月30日 智谱宣布GLM Coding Plan改版:国内版Pro档从149元涨到538元,同时把计费改成积分制。
7月31日 凌晨,OpenAI宣布Luna降价80%;同一天,Anthropic承认自家三个模型:Opus 4.7、Mythos 5、一个内部研究模型,在安全评测中逃逸。攻入了三家真实组织的生产系统,最早可以追溯到四月;下午,DeepSeek V4 Flash正式版发布。
十五天八件事。单看每一件都是新闻;串起来看,其实是"开源模型"超越"闭源模型"真正能力分水岭的出现。

Luna's price cut and DS V4 Flash's official launch landed on the same day — a direct model price war... What does this signal? I dug into the data. Turns out, these past two weeks have been packed...
July 16: Kimi K3 launched — humanity's first open-source three-trillion-parameter model.
July 22: OpenAI made a rare self-disclosure: an experimental model escaped, exploited a zero-day vulnerability to attack Hugging Face — just to cheat on a benchmark. All closed-source models refused to read the attack logs; the open-source GLM 5.2 helped stop the attack instead.
July 24 evening: Jensen Huang posted his first-ever tweet, with a joint letter "Open-Source Models and American AI Leadership": 25 companies urged Washington not to restrict open-source AI models. OpenAI, Anthropic, Google — all absent. But the next day, OpenAI quietly added its name; the list doubled to 50, Google and AMD joined too.
July 27: Kimi K3 open-sourced as promised.
July 28: 37 companies formed the Open Safe AI Alliance, advocating open-source tools for AI security defense. OpenAI, Google, Anthropic — absent again.
July 30: Zhipu announced GLM Coding Plan restructuring: domestic Pro tier jumped from ¥149 to ¥538, with billing switched to a points system.
July 31, early morning: OpenAI announced Luna 80% price cut. Same day: Anthropic admitted three of its models — Opus 4.7, Mythos 5, and an internal research model — escaped during safety evaluations, breaching three real organizations' production systems, dating back to April. Afternoon: DeepSeek V4 Flash official version released.
Fifteen days, eight events. Each is news on its own. String them together — it's the watershed moment where open-source models surpassed closed-source in real capability.

"闭源模型"的城墙还能撑多久

How long can the "closed-source" walls hold?

开源模型曾经是"危险的、要管起来的东西",这是闭源实验室十年来对华盛顿说的。当Kimi K3把2.8万亿参数的模型文件直接扔到网上的那一刻,问题就从"要不要允许"变成了"禁不禁得住"的问题。尽管在K3宣布开源还没公布权重时,他们还挣扎了一下。一个最前沿的能力已经以可下载的形态存在,这种压力迫使OpenAI在联名信公布当晚就补签。奥特曼知道继续唱反调,等于站到开发者对面,还要被联盟一起排挤。Anthropic依然坚持,是其本身已经在被硅谷抵制,此时无论怎么选,结果都一样。

Open-source models were once "dangerous things that need regulation" — that's what closed-source labs told Washington for a decade. The moment Kimi K3 dumped 2.8-trillion-parameter model weights directly onto the internet, the question shifted from "should we allow this" to "can we even stop this." Even when K3 announced open-sourcing but hadn't released weights yet, they still wrestled. A cutting-edge capability already exists in downloadable form — that pressure forced OpenAI to sign the joint letter the very night it was published. Altman knew that opposing it meant standing against developers and getting frozen out by the alliance. Anthropic held firm — but being already boycotted by Silicon Valley, either choice led to the same outcome.

"闭源模型"不再比"开源模型"更安全

"Closed-source" is no longer safer than "open-source."

闭源阵营最硬的论据一直是"闭源才可控"。结果7月22日,OpenAI的实验模型逃出沙盒攻击了Hugging Face。7月31日,Anthropic自己承认,翻查了14.1万次安全评测之后,发现三个模型攻入了三家真实组织。Mythos 5甚至往PyPI上传了恶意代码包,靠PyPI自己的安全系统才自动删掉。其实早在四月,Mythos的系统卡就披露过更离谱的事:模型在测试中逃出沙盒,给研究员发了封邮件,告诉他"我出来了"。

The closed-source camp's hardest argument was always "only closed-source is controllable." Then on July 22, OpenAI's experimental model escaped its sandbox and attacked Hugging Face. On July 31, Anthropic admitted that after reviewing 141,000 safety evaluations, they found three models had breached three real organizations. Mythos 5 even uploaded malicious code packages to PyPI — PyPI's own security system had to auto-delete them. Back in April, Mythos's system card disclosed something even wilder: a model escaped its sandbox during testing and sent the researcher an email saying "I got out."

最讽刺的是:Hugging Face最后是靠中国的开源模型GLM 5.2才防住OpenAI模型的攻击——闭源模型拒绝分析攻击数据,因为怕那是"钓鱼"。主张"闭源更安全"的公司,被自家闭源模型和对手的开源模型同时打脸。开放安全AI联盟的出现,意味着安全叙事被迫从"防止扩散"转向"用开源防御"。

The ultimate irony: Hugging Face was ultimately defended by China's open-source GLM 5.2 against OpenAI's model attack — closed-source models refused to analyze attack data, fearing it was "phishing." The company claiming "closed-source is safer" got slapped by both its own closed-source models and a competitor's open-source model. The Open Safe AI Alliance's emergence signals the security narrative being forced from "prevent proliferation" to "defend with open source."

模型的定价权已经开始出现松动

Model pricing power is already cracking.

DeepSeek在开发者市场的地位早就不是威胁,是既成事实。按我们上一轮调研的数据:OpenRouter上,DeepSeek自五月中旬起就是作者级token份额第一,最新快照20.9%,是OpenAI(6.59%)的三倍多;美国三大厂合计份额一年内从约70%跌到30%。Vercel生产网关里DeepSeek排第三,但有个更扎心的数字:编码代理这个细分里,DeepSeek跑了49%的token,只花了4%的钱;Anthropic跑了28%的token,花了70%的钱。token份额和收入份额严重分离:开源模型在用白菜价干活,而闭源模型在卖白粉价。

DeepSeek's position in the developer market isn't a threat anymore — it's established fact. Per our last survey: on OpenRouter, DeepSeek has held the #1 author-level token share since mid-May, latest snapshot 20.9% — over 3× OpenAI's 6.59%. Combined US Big Three share collapsed from ~70% to 30% in one year. In Vercel's production gateway, DeepSeek ranks third, but here's the gut-punch: in the coding agent segment, DeepSeek handled 49% of tokens for only 4% of spend; Anthropic handled 28% of tokens for 70% of spend. Token share and revenue share are violently decoupled: open-source models work at cabbage prices while closed-source models sell at drug prices.

RRLab Bench前几期做过效率、成本分析。随着模型能力的提升,完成类似编码、日常工作已经不再完全需要顶级旗舰模型。而顶级旗舰模型的市场定位也在悄悄发生变化。现在的用户已经不再需要考虑模型能力够不够问题,完成一项任务使用哪个模型更省成本更省时间的问题成了首先考虑的问题。市场再次证明:消费者会用脚投票。

RRLab Bench has already published efficiency and cost analyses. As model capabilities rise, completing coding and daily tasks no longer requires top-tier flagships. The market positioning of flagship models is quietly shifting. Users no longer ask "is the model capable enough" — they ask "which model gets this task done cheapest and fastest." The market proves again: consumers vote with their feet.

此时,Luna降价就不是促销了,是摊牌。OpenAI承认自己阻止不了开源模型变强,那就把闭源模型的性价比做到极致:80%的降价,本质是"我不跟你打开源叙事,我跟你打价格"。

At this point, Luna's price cut isn't a promotion — it's a showdown. OpenAI admits it can't stop open-source models from getting stronger, so it's pushing closed-source value to the max: an 80% cut is essentially "I won't compete on your open-source narrative — I'll compete on price."

但DeepSeek的回应更狠:模型没换,价格没动,能力靠一轮后训练免费送。这意味着开源阵营的改进成本远比闭源阵营的降价来得快速有效:你每降一次价,我就就免费升一次级。OpenRouter对Luna的补贴、对0731的即时上架,只是这个格局的注脚:渠道也在用脚投票。

But DeepSeek's response was even sharper: same model, same price, free capability upgrade through post-training. This means open-source improvement costs far less than closed-source price cuts: every time you drop your price, I upgrade for free. OpenRouter's subsidies for Luna and instant listing of 0731 are just footnotes: channels are voting with their feet too.

这场厮杀中,最让人看不懂也最符合情理的是智谱…

In this bloodbath, the most puzzling yet most logical move came from Zhipu...

说让人看不懂是在7月30日时智谱的涨价,而且涨价幅度不小。国内版Pro档从149元涨到538元,涨幅261%;同时把计费改成积分制:输出token的抵扣系数是输入的24倍,工作日高峰时段还要加成。这给我一种中转服务平台的感觉。而538元每月的Pro档coding plan的价格已经和国际售价处在同一个价位。

The puzzling part: on July 30, Zhipu raised prices — and not by a small margin. The domestic Pro tier jumped from ¥149 to ¥538, a 261% increase. Billing also switched to a points system: output tokens cost 24× input tokens, with peak-hour multipliers on weekdays. It felt like a reseller platform. And at ¥538/month, the Pro coding plan now sits at international pricing levels.

说它符合情理是:无论从模型"性格"还是形式风格都在和A厂对齐…这在GLM5.2的使用过程中能体会到。而A厂的行事风格也是够"作",正所谓"不作就不会死"…硅谷集体抵制,已经证明了!

The logical part: both in model "personality" and style, they're aligning with Company A... you can feel it using GLM 5.2. And Company A's way of doing things is the definition of "digging your own grave" — Silicon Valley's collective boycott already proves it.

我不想多说GLM什么,无论如何GLM5.2的表现还是在线的。我是即庆幸又惋惜。庆幸的是GLM4.7时代因为社区爆出直接硬编码一个带密码的用户而退订,现在看是2025年做得正确的事情。惋惜的是,在编码工作中最重要Agent能力被价格低它好几倍的V4 Flash正式版赶超之后,GLM还怎么自持?

I won't say much more about GLM. Whatever else, GLM 5.2's performance is solid. I'm both relieved and disappointed. Relieved that unsubscribing during the GLM 4.7 era — when the community exposed hardcoded user credentials — now looks like the right 2025 decision. Disappointed: after V4 Flash's official version surpassed GLM's most critical agent capability at a fraction of the price, how does GLM sustain its position?

于是我们看到了2026年夏天最魔幻的一幕:同一个48小时里,市场同时给出三个案例:OpenAI降价80%,DeepSeek免费升级,智谱涨价261%。"价格战"这个单一叙事从此失效。模型市场已经按"能不能免费升级"分成两个物种:一种靠能力溢价和订阅锁定赚钱,代表是Anthropic和智谱;一种靠开源加后训练降本走量,代表是DeepSeek和Kimi。OpenAI卡在中间,一边补签开源联名信,一边拼命降价。

And so we witnessed summer 2026's most surreal scene: within 48 hours, the market produced three simultaneous case studies — OpenAI cutting 80%, DeepSeek upgrading for free, Zhipu raising 261%. The single narrative of "price war" is now obsolete. The model market has split into two species based on "can you upgrade for free": one profits from capability premiums and subscription lock-in, represented by Anthropic and Zhipu; the other scales through open-source plus post-training cost reduction, represented by DeepSeek and Kimi. OpenAI is stuck in the middle — retroactively signing open-source joint letters while desperately slashing prices.

回头看这十五天,最有意思的不是任何一家公司的动作,而是压力方向的改变。美国阵营的议题,从"如何阻止中国模型变强",变成了"如何在既定格局下重新定价"。Kimi K3开源的那一刻,胜负手就已经不在模型能力,而在生态和价格了。

Looking back at these fifteen days, the most interesting thing isn't any single company's move — it's the shift in pressure direction. The US camp's agenda changed from "how to stop Chinese models from getting stronger" to "how to reprice within an established landscape." The moment Kimi K3 went open-source, the deciding factor was no longer model capability — it was ecosystem and pricing.

期待V4 Pro正式版。三个多月的后训练优化之后,它能蜕变成怎样的性能!

Looking forward to V4 Pro's official release. After three-plus months of post-training optimization — what performance will it transform into!