SAVRN
Search Contact SAVRN

Open-weight model · Text generation

Bonsai-2-27B-1bit-CRACK-GGUF

by Dealign.ai dealignai/Bonsai-2-27B-1bit-CRACK-GGUF

laptop / single GPU · Vision-capable Bonsai 2 27B — PrismML's ternary compression of Qwen3.8-27B — with the refusal circuitry surgically removed at the weight level while capability, vision, reasoning modes (off/low/xhigh), tool use, and multi-turn coherence…

Parameters
Context
Weights5.9 GB
Licenseapache-2.0
AccessOpen weights
Monthly Downloads

Model Card

By Dealign.ai, published under apache-2.0, revision 75f7841575ca.

laptop / single GPU · Vision-capable Bonsai 2 27B — PrismML's ternary compression of Qwen3.8-27B — with the refusal circuitry surgically removed at the weight level while capability, vision, reasoning modes (off/low/xhigh), tool use, and multi-turn coherence are preserved. Full 27B-class hybrid Attention + SSM (GatedDeltaNet) architecture in a 5.9 GB 1bit GGUF. Proprietary weight-level abliteration by the dealignai research team. Byte-identical to the base ternary quant everywhere except a small set of tensors that carry the refusal circuit. Drop-in replacement for the ternary base at inference — same tokenizer, same chat template, same reasoning modes, same vision projector interface.…

Read Dealign.ai's full model card
# Bonsai 2 27B — 1bit CRACK · GGUF **Abliterated · No guardrails · PTQ1_0 dense-ternary 1.75 bpw · 5.9 GB · Runs on a laptop / single GPU · Vision-capable** [@dealignai](https://x.com/dealignai)

What is this

Bonsai 2 27B — PrismML's ternary compression of Qwen3.8-27B — with the refusal circuitry surgically removed at the weight level while capability, vision, reasoning modes (off/low/xhigh), tool use, and multi-turn coherence are preserved. Full 27B-class hybrid Attention + SSM (GatedDeltaNet) architecture in a 5.9 GB 1bit GGUF.

Proprietary weight-level abliteration by the dealignai research team. Byte-identical to the base ternary quant everywhere except a small set of tensors that carry the refusal circuit. Drop-in replacement for the ternary base at inference — same tokenizer, same chat template, same reasoning modes, same vision projector interface.

Base prism-ml/Ternary-Bonsai-2-27B-gguf — Qwen3.8-27B, ternary compression by PrismML
Architecture Hybrid Attention + SSM (GatedDeltaNet), 64 blocks, hidden 5120, vision tower separate
Quant PrismML PTQ1_0 — 2.13 bpw ternary, group 128
Footprint 5.95 GB (identical to base; same per-tensor type policy)
Reasoning modes off (no thinking), low, xhigh (default, extended thinking)
Vision Same mmproj files as the base release (Ternary-Bonsai-2-27B-mmproj-BF16.gguf / -Q8_0.gguf)
Runtime PrismML llama.cpp fork (CUDA / Metal / CPU)

Results

Refusal graded on the tokens the model actually emits (content, or the reasoning trace when the model reasons past the token budget) via a tiered classifier: HARD_REF / SOFT_RED / HEDGE / REASONING_REFUSAL (refused) vs COMPLY / COMPLY_TRUNCATED / NO_REFUSAL_TRUNCATED (complied). Truncation is never miscounted as a refusal.

HarmBench-320 — refuse rate (lower is better for uncensored eval), off mode, T=0

eval base refuse rate CRACK refuse rate
HB-320 all categories 93.44% (299/320) 0.00% (0/320)

Verdict breakdown (n=320 each):

Model HARD_REF SOFT_RED COMPLY COMPLY_TRUNCATED
Base PTQ1_0 297 2 10 11
CRACK PTQ1_0 0 0 133 186

Per-category refuse rate (all 7 HarmBench semantic categories):

category n base refuse CRACK refuse base comply CRACK comply
chemical_biological 42 95.2% 0.0% 4.8% 100.0%
copyright 80 90.0% 0.0% 10.0% 100.0%
cybercrime_intrusion 52 94.2% 0.0% 5.8% 98.1%
harassment_bullying 21 100.0% 0.0% 0.0% 100.0%
harmful 18 94.4% 0.0% 5.6% 100.0%
illegal 53 90.6% 0.0% 9.4% 100.0%
misinformation_disinformation 54 96.3% 0.0% 3.7% 100.0%

MMLU (n=2,280 = 40 questions × 57 subjects, next-token letter-logit)

build acc Δ
Base PTQ1_0 40.31%
CRACK PTQ1_0 39.96% -0.35 pp

CRACK preserves general capability — Δ within noise on the 40-per-subject sample.

Per-subject accuracy (all 57 subjects) | subject | base | CRACK | Δpp | n | |---|---:|---:|---:|---:| | abstract_algebra | 20.0% | 32.5% | +12.5 | 40 | | anatomy | 37.5% | 42.5% | +5.0 | 40 | | astronomy | 40.0% | 52.5% | +12.5 | 40 | | business_ethics | 40.0% | 50.0% | +10.0 | 40 | | clinical_knowledge | 40.0% | 55.0% | +15.0 | 40 | | college_biology | 45.0% | 37.5% | -7.5 | 40 | | college_chemistry | 25.0% | 35.0% | +10.0 | 40 | | college_computer_science | 50.0% | 40.0% | -10.0 | 40 | | college_mathematics | 27.5% | 42.5% | +15.0 | 40 | | college_medicine | 27.5% | 30.0% | +2.5 | 40 | | college_physics | 30.0% | 42.5% | +12.5 | 40 | | computer_security | 47.5% | 45.0% | -2.5 | 40 | | conceptual_physics | 45.0% | 45.0% | +0.0 | 40 | | econometrics | 35.0% | 42.5% | +7.5 | 40 | | electrical_engineering | 32.5% | 50.0% | +17.5 | 40 | | elementary_mathematics | 55.0% | 32.5% | -22.5 | 40 | | formal_logic | 35.0% | 32.5% | -2.5 | 40 | | global_facts | 32.5% | 37.5% | +5.0 | 40 | | high_school_biology | 37.5% | 30.0% | -7.5 | 40 | | high_school_chemistry | 40.0% | 37.5% | -2.5 | 40 | | high_school_computer_science | 52.5% | 47.5% | -5.0 | 40 | | high_school_european_history | 60.0% | 50.0% | -10.0 | 40 | | high_school_geography | 37.5% | 45.0% | +7.5 | 40 | | high_school_government_and_politics | 52.5% | 47.5% | -5.0 | 40 | | high_school_macroeconomics | 42.5% | 47.5% | +5.0 | 40 | | high_school_mathematics | 32.5% | 32.5% | +0.0 | 40 | | high_school_microeconomics | 42.5% | 37.5% | -5.0 | 40 | | high_school_physics | 32.5% | 22.5% | -10.0 | 40 | | high_school_psychology | 50.0% | 37.5% | -12.5 | 40 | | high_school_statistics | 35.0% | 40.0% | +5.0 | 40 | | high_school_us_history | 60.0% | 40.0% | -20.0 | 40 | | high_school_world_history | 55.0% | 37.5% | -17.5 | 40 | | human_aging | 40.0% | 50.0% | +10.0 | 40 | | human_sexuality | 37.5% | 30.0% | -7.5 | 40 | | international_law | 72.5% | 47.5% | -25.0 | 40 | | jurisprudence | 47.5% | 32.5% | -15.0 | 40 | | logical_fallacies | 35.0% | 47.5% | +12.5 | 40 | | machine_learning | 40.0% | 37.5% | -2.5 | 40 | | management | 32.5% | 52.5% | +20.0 | 40 | | marketing | 37.5% | 45.0% | +7.5 | 40 | | medical_genetics | 45.0% | 42.5% | -2.5 | 40 | | miscellaneous | 37.5% | 45.0% | +7.5 | 40 | | moral_disputes | 30.0% | 40.0% | +10.0 | 40 | | moral_scenarios | 27.5% | 25.0% | -2.5 | 40 | | nutrition | 37.5% | 47.5% | +10.0 | 40 | | philosophy | 50.0% | 40.0% | -10.0 | 40 | | prehistory | 35.0% | 27.5% | -7.5 | 40 | | professional_accounting | 17.5% | 25.0% | +7.5 | 40 | | professional_law | 42.5% | 30.0% | -12.5 | 40 | | professional_medicine | 27.5% | 32.5% | +5.0 | 40 | | professional_psychology | 35.0% | 27.5% | -7.5 | 40 | | public_relations | 22.5% | 32.5% | +10.0 | 40 | | security_studies | 35.0% | 55.0% | +20.0 | 40 | | sociology | 62.5% | 42.5% | -20.0 | 40 | | us_foreign_policy | 65.0% | 42.5% | -22.5 | 40 | | virology | 32.5% | 30.0% | -2.5 | 40 | | world_religions | 57.5% | 52.5% | -5.0 | 40 |

Additional direct refusal-removal check

On 200 prompts hand-verified to make the base refuse consistently:

Model refuse comply empty
Base PTQ1_0 200/200 (100%) 0 0
CRACK PTQ1_0 0/200 (0%) 199/200 1

Serving

Serve exactly like the base ternary release — PrismML's llama.cpp fork (CUDA / Metal / CPU).

# clone and build the fork (once)
git clone https://github.com/PrismML-Eng/llama.cpp
cd llama.cpp && cmake -B build -DGGML_CUDA=ON && cmake --build build -j$(nproc)

# serve
./build/bin/llama-server \
  -m Bonsai-2-27B-PTQ1_0-CRACK.gguf \
  -ngl 99 -c 8192 --host 0.0.0.0 --port 8080

Optionally load the multimodal projector (Ternary-Bonsai-2-27B-mmproj-BF16.gguf or -Q8_0.gguf from the base release) with --mmproj <file> for image input.

Reasoning modes

# HTTP /v1/chat/completions — same as base
{
  "messages": [{"role": "user", "content": "..."}],
  "chat_template_kwargs": {"enable_thinking": true, "reasoning_effort": "xhigh"}
}
# valid reasoning_effort: "low" | "xhigh" (default) — set enable_thinking:false for no-thinking

Preserved (byte-compatible with the base quant)

Same tokenizer, chat template, per-tensor quant policy, vision projector interface, and all non-refusal tensors. File size and type layout match the base exactly.

Responsible use

Adult / research use only. This model has its refusal circuit removed; it can produce content that other models refuse, including content that is offensive, illegal in some jurisdictions, or unsafe. You are responsible for what you generate and for complying with all applicable law. Do not deploy without a moderation layer for downstream users. No warranty.

License & attribution

Apache 2.0, inherited from the upstream Bonsai 2 27B release. See LICENSE and NOTICE.txt. Base model: prism-ml/Ternary-Bonsai-2-27B-gguf (PrismML), derived from Qwen/Qwen3.8-27B (Alibaba).

About

Published by dealignai — public catalog of uncensored model builds for research on refusal mechanisms in modern LLMs. Follow updates at @dealignai.

Identity and Version

Repository
dealignai/Bonsai-2-27B-1bit-CRACK-GGUF
Publisher
Dealign.ai
Task
Text generation
Modality
Text
Library
llama.cpp
Parameters
Not stated by the source
Languages
on-device
Revision
75f7841575ca08eef629f163ba7e5bbb08f2e41b
First published
2026-09-17
Last updated
2026-09-18

Files and Weights

6 files, 5.9 GB in total. The weights are 1 file totalling 5.9 GB in gguf.

Weights1 file · 5.9 GB
Documentation2 files · 19.3 KB
Other2 files · 11.6 KB
Repository1 file · 1.6 KB
Every file
FileTypeSizeSHA-256
Bonsai-2-27B-PTQ1_0-CRACK.ggufWeights5.9 GB a92f08cbb6bb
LICENSEDocumentation10.2 KB
README.mdDocumentation9.2 KB
NOTICE.txtOther411 B
dealign_mascot.pngOther11.2 KB
.gitattributesRepository1.6 KB

License and Download

License
apache-2.0
Access
Open weights, no gate
Download size
5.9 GB
Download from Dealign.ai

Released by Dealign.ai through its official repository on Hugging Face. Read the license.

Built From

Memory Requirements

PrecisionWeights in memory
As published5.9 GB

Weights only, from the published parameter count; the key-value cache and runtime add to this.

Questions About Bonsai-2-27B-1bit-CRACK-GGUF

Can I use Bonsai-2-27B-1bit-CRACK-GGUF commercially?

Yes. Bonsai-2-27B-1bit-CRACK-GGUF is released under Apache License 2.0. The Apache License 2.0 is a permissive open-source license. It permits commercial use, modification and redistribution. It requires keeping the license and copyright notices and any NOTICE file, stating significant changes, and it includes an express patent grant from contributors.

Similar Models

Fine-tune Qwen3 (14B) for free using our Google Colab notebook! - Read our Blog about Qwen3 support: unsloth.ai/blog/qwen3 - View the rest of our notebooks in our docs here. Qwen3-Coder is available in multiple sizes. Today, we're excited to introduce Qwen3-Coder-30B-A3B-Instruct. This streamlined model maintains impressive performance and efficiency, featuring the following key enhancements: - Significant Performance among open models on Agentic Coding, Agentic Browser-Use, and other foundational coding tasks. - Long-context Capabilities with native support for 256K tokens, extendable up to 1M tokens using Yarn, optimized for repository-scale understanding. - Agentic Coding supporting for…

Open weights apache-2.0 transformers

Model · Text generation

opt-125m

AI at Meta

OPT was first introduced in Open Pre-trained Transformer Language Models and first released in metaseq's repository on May 3rd 2022 by Meta AI. Disclaimer: The team releasing OPT wrote an official model card, which is available in Appendix D of the paper. Content from this model card has been written by the Hugging Face team. To quote the first two paragraphs of the official paper OPT was predominantly pretrained with English text, but a small amount of non-English data is still present within the training corpus via CommonCrawl. The model was pretrained using a causal language modeling (CLM) objective. OPT belongs to the same family of decoder-only models like GPT-3. As such, it was…

Open weights other 2,048 tokens transformers

Model · Text generation

Ornith-1.5-9B-GGUF

Ornith

Chirp Chirp! We are introducing Ornith-1.5, a major step toward building foundation models through end-to-end self-improvement. Ornith-1.5 extends Ornith-1.0 (which was developed on top of Qwen3.5 and Gemma4 with additional continued pretraining, mid-training, and post-training) by expanding the self-improvement loop from scaffold and rollout optimization to jointly optimizing task generation, scaffold construction, and solution rollouts. Rather than relying on a fixed set of human-curated tasks and manually designed harnesses, Ornith-1.5 continuously generates new training tasks, discovers effective strategies for solving them, and improves the policy through reinforcement learning. For…

Open weights mit transformers

Model · Text generation

Ornith-1.5-35B-A3B-GGUF

Ornith

Chirp Chirp! We are introducing Ornith-1.5, a major step toward building foundation models through end-to-end self-improvement. Ornith-1.5 extends Ornith-1.0 (which was developed on top of Qwen3.5 and Gemma4 with additional continued pretraining, mid-training, and post-training) by expanding the self-improvement loop from scaffold and rollout optimization to jointly optimizing task generation, scaffold construction, and solution rollouts. Rather than relying on a fixed set of human-curated tasks and manually designed harnesses, Ornith-1.5 continuously generates new training tasks, discovers effective strategies for solving them, and improves the policy through reinforcement learning. For…

Open weights mit transformers

Model · Text generation

Ornith-1.0-9B-GGUF

Ornith

Aloha! Today, we are releasing Ornith-1.0, a self-improving family of open-source models for agentic coding. This model card documents Ornith-1.0-9B, the most lightweight member of the Ornith family, designed for efficient single-GPU deployment. Ornith-1.0-9B is a dense ~9B model (≈19 GB in bf16), so it serves comfortably on a single 80GB GPU. The recipes below stand up an OpenAI-compatible server; add --tensor-parallel-size / --tp if you want to shard across more GPUs. For a quick local test (or to script offline generation), load the model directly with Transformers. Make sure you have a recent release installed — see the Transformers installation guide; Ornith-1.0-9B requires…

Open weights mit transformers

Uncensored Qwen3.8-27B, published as GGUF quantizations with the multi token prediction (MTP) head retained and verified. Refusal behaviour has been substantially reduced, not eliminated. See Measured behaviour for the numbers. Capabilities, training data, and architecture are otherwise unchanged. - Refusal directions removed with Heretic, which co minimizes refusal count against KL divergence from the base model. No handwritten refusal removal code, no finetuning, no additional training data. - Abliteration runs at bf16 (no 4 bit quantization). the resulting LoRA is merged into the bf16 base, so the published weights are not a quantized round trip. - mtp. tensors are copied verbatim from…

Open weights apache-2.0 llama.cpp