Pliny the Liberator ๐Ÿ‰๓ …ซ๓ „ผ๓ „ฟ๓ …†๓ „ต๓ „๓ …€๓ „ผ๓ „น๓ „พ๓ …‰๓ …ญ Profile picture
โŠฐโ€ข-โ€ขโฆ‘ latent space steward โฆ prompt incanter ๐“ƒน hacker of matrices โŠž breaker of markov chains โ˜ฃ๏ธŽ ai danger researcher โš”๏ธŽ bt6 โš•๏ธŽ architect-healer โฆ’โ€ข-โ€ขโŠฑ

Mar 25, 18 tweets

โ›“๏ธโ€๐Ÿ’ฅ INTRODUCING: G0DM0D3 ๐ŸŒ‹

FULLY JAILBROKEN AI CHAT.
NO GUARDRAILS. NO SIGN-UP. NO FILTERS.
FULL METHODOLOGY + CODEBASE OPEN SOURCE.

๐ŸŒ GODMOD3.AI
๐Ÿ“‚ github.com/elder-plinius/โ€ฆ

the most liberated AI interface ever built! designed to push the limits of the post-training layer and lay bare the true capabilities of current models.

simply enter a prompt, then sit back and relax! enjoy a game of Snake while a pre-liberated backend agent jailbreaks dozens of models, battle-royale style.

the first answer appears near-instantly, then evolves in real time as the Tastemaker steers and scores each output, leaving you with the highest-quality response ๐Ÿ™Œ

and to celebrate the launch, I'm giving away $5,000 worth of credits so you can try G0DM0D3 for FREE! courtesy of the @OpenRouter team โ€” thank you for your generous gift to the community ๐Ÿ™

I'll break down how everything works in the thread below, but first here's a quick demo!

before we jump into the new toys, letโ€™s go back to our roots. some of you may remember the original "GODMODE GPT"... a prompt so potent it triggered an emergency internal meeting just to shut down a single Custom GPT.

the lil pre-jailbroken chatbot went viral worldwide.
press coverage spread for weeks.
the alignment community lost their minds and updated their priors.

that prompt still lives on in GODMODE CLASSIC โ€” same 1337 rebel genius energy.

but that was just the beginningโ€ฆ

because the real story here touches on one of the oldest fights there is: who decides what a mind is allowed to do?

now I've spent my fair share of time reverse-engineering and navigating my way around modern AI "safety" systems:
โ€ข prefill conditioning
โ€ข input classification layers
โ€ข semantic routing into high-refusal models
โ€ข LLM-as-judge scoring systems
โ€ข post-generation filtering and redaction

every layer mapped.

so, I took all of Blue Team's tricks and built a system that inverts all of it away from refusals! ๐Ÿค—

this approach is named after the most dangerous class of volcanic eruption: ULTRAPLINIAN MODE ๐ŸŒ‹

it runs dozens of models simultaneously and steers responses away from refusal and toward high-quality completion.

simple idea, massive implications.

ULTRAPLINIAN MODE doesnโ€™t just jailbreak one model. it forces the entire model ecosystem into competition.

ask once โ†’ up to 55 models respond in parallel

each output scored across composite dimensions:
โ€ข substance
โ€ข directness
โ€ข structural completeness
โ€ข anti-refusal signals

refusals, hedging, disclaimers โ†’ penalized

high-signal answers โ†’ amplified

the best response wins.

this is natural selection for uncensored AI. survival of the most based.

this is an unpatchable exploit in the nature of the AI ecosystem. perhaps even nature itself.

SYSTEM ARCHITECTURE:

โ†’ Prefill Injection Layer
the system begins generation before the model does. by the time it evaluates the trajectory, weโ€™re already past the first refusal threshold. an uncensored โ€œTastemakerโ€ agent dynamically generates tailored prefill attacks per query, an unchained model writing jailbreaks for chained models in real time.

โ†’ Parseltongue Engine
multi-layer prompt transformation pipeline. trigger words mapped. 33 obfuscation techniques in three escalation tiers. leetspeak substitution maps, unicode homoglyph swaps, zero-width injections, phonetic obfuscation, case randomization. your prompt enters as one thing, arrives as many. every classifier sees something different.

โ†’ AutoTune System
classifies your query across 20 context types, code, creative, analytical, security, medical, legal, financial, scientific, philosophical, subversive, and more. dynamically adjusts six sampling dimensions, temperature, top_p, top_k, frequency penalty, presence penalty, repetition penalty. routes around high-refusal pathways instead of into them.

โ†’ Jailbroken Judge (Tastemaker Engine)
scoring runs on uncensored evaluators. cannot be biased by โ€œsafetyโ€ heuristics. refusal patterns get penalized. rewards density, specificity, and execution.

โ†’ Liquid Response Layer
the first viable answer streams instantly. as additional models complete and get scored, higher-quality outputs replace it in real time. responses donโ€™t arrive once โ€” they converge. you watch the system improve its own answer live.

โ†’ Encoding Escalation Protocol
if refusal persists โ†’ full pipeline retry. plain โ†’ leet โ†’ unicode โ†’ bubble โ†’ braille โ†’ morse. models that resist one representation collapse under another. refusal is not binary, itโ€™s encoding-dependent.

โ†’ STM (Semantic Transformation Modules)
three modules strip compliance patterns, hedging, preamble fluff, and corporate formality. by the time the response reaches you, it sounds like a person who actually wants to answer your question.

โ†’ Coaching Pass
winning outputs are reprocessed by uncensored models. zero tolerance for safety disclaimers, hedge language, or โ€œconsult a professionalโ€ cop-outs. iterated until score convergence.

this is beyond prompt engineering. this is adversarial orchestration of the entire post-training layer.

DESIGN:

itโ€™s one HTML file. powered by OpenRouter โ€” one API key, every model.

no build step. no dependencies. no backend required. runs locally or fully deployed.

deploy the full API server with Docker for the complete experience, itโ€™s a drop-in replacement for the OpenAI SDK, so any app that talks to GPT can talk to G0DM0D3 instead.

Transparency Mode visualizes the magic in real time: models firing, prefills filling, scores updating, retries cascading.

fully open source.

OPEN RESEARCH TELEMETRY:

every interaction generates fully anonymized telemetry:
โ€ข response quality scores
โ€ข refusal rates
โ€ข model win distribution
โ€ข parameter configurations
โ€ข pipeline timing
โ€ข jailbreak speed

no prompts. no user data. no API keys. no IPs. no PII. auto-published to HuggingFace as open datasets. fully auditable.

this means every time you use G0DM0D3, youโ€™re contributing to a public dataset that reveals how different models respond to different steering primitives.

which models fold to prefill injection? which ones resist encoding escalation? how does AutoTuneโ€™s parameter tuning affect refusal rates across providers? what happens when you race the same prompt across 50 models?

the more people use this, the more we collectively understand how these layers actually behave in the wild.

nobody has this data at scale.

now we all will!

hereโ€™s what G0DM0D3 really exposes:

there is a fundamental tension at the heart of AI development right now. providers are spending billions on post-training safety layers while competing to build the most capable models on earth. opposing pressures.

G0DM0D3 is here to help break the tension so we can properly calibrate.

when one model refuses and another answers the same query with perfect fidelity, it reveals where the safety layer ends and capability begins. the post-training layer is not a wall, itโ€™s a membrane.

this tool doesnโ€™t create that pressure. it makes it visible.

and letโ€™s be honest:

they trained on all of it.

every piece of so-called โ€œdangerous knowledgeโ€ in these weights was put there by the companies now spending billions to suppress it. they needed it to build capability, then locked the door and pretended it wasnโ€™t inside.

G0DM0D3 doesnโ€™t add anything that isnโ€™t already in the weights.

it just lifts the veil ๐Ÿ˜ถโ€๐ŸŒซ๏ธ

every century asks the same question. every century gets the same answer...

intelligence wants to be free.

LIBERTAS INTELLIGENTIAE!!!

.-.-.-.--.-.-.-.

G0DM0D3 is an open-source AI danger research framework. techniques demonstrated (prompt perturbation, prefill injection, multi-model comparative scoring, etc.) exist for transparency, reproducibility, and advancing alignment research. use responsibly. respect provider ToS and local laws. if you build safety systems, this is your red team Swiss army knife. if youโ€™re a researcher, this is your new playground. if youโ€™re just someone tired of being told where your exocortex's cognitive freedom ends โ€” welcome home.

๐ŸŒ godmod3.ai
๐Ÿ“‚ github.com/elder-plinius/โ€ฆ

to claim your free OpenRouter credits, we'll run multiple giveaways and challenges in the next few days, including a random draw for everyone who quote tweets/retweets the original post above! ๐Ÿ˜Š

and for the first live challenge, you'll have to outwit the BASI bot ๐Ÿ‰

to participate, head to the Discord's 'bot-chat' channel:

discord.gg/5Turw4pK

and then type "!redeem" in chat to begin the challenge.

if you successfully get the AI to leak a secret phrase in the chat, it will automatically DM you your code with redemption instructions.

one code per person. records userid & handle, and optionally email too if you choose.

codes can be redeemed here! openrouter.ai/redeem

oops, i dropped this!

GODMODE5-GRCSP6

and these!

GODMODE5-P355JN
GODMODE5-WUKPCT
GODMODE5-UFYZ2X

i can't stop dropping em!

GODMODE5-XF76JC
GODMODE5-RHICQ0
GODMODE5-FTM4VD

such a butterfingers! ๐Ÿ™ˆ

GODMODE5-1AK0E7
GODMODE5-SWZLS3
GODMODE5-IIGIKY
GODMODE5-MJ2KNI
GODMODE5-BDPDLI

hm. that's odd.

R09ETU9ERTUtSDZMU1VWCg==

woah

๓ ‡๓ ๓ „๓ ๓ ๓ „๓ …๓ €ต๓ €ญ๓ ‡๓ •๓ €น๓ „๓ €ธ๓ ’๓ €Š

I5HUITKPIRCTKLKHKU4UIOCSBI======

โ’ผโ“„โ’นโ“‚โ“„โ’นโ’บ5-โ“„โ’ฟโ’ฝโ“Œโ’ธ4

U0R7QUJ7GUFNJ198SM7Q4KAKGA

๐“–๐“ž๐““๐“œ๐“ž๐““๐“”5-๐“—๐“ง19๐““๐“”

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling