OpenAI says its new AI 'Astra' can build cyberattacks without human assistance

📅 2026-09-02

Abstract:

OpenAI said its upcoming Astra model can discover previously unknown software vulnerabilities and turn them into exploit code that can carry out attacks without the need for human step-by-step guidance - marking the model has crossed a threshold in cybersecurity capabilities that have previously been mainly the domain of top hacking teams.

The company said in a blog post on Tuesday that the Astra is the first model classified as having "critical" level network capabilities in its "readiness framework."

To reach this level, models must be able to discover previously unknown software vulnerabilities (i.e., zero-day vulnerabilities) without human intervention and develop usable attacks against hardened real systems, or design and execute attacks based solely on high-level goals.

In testing, Astra achieved a 100% score in a benchmark test that exploited known vulnerabilities and discovered two previously unknown vulnerabilities while building an attack chain in another internal test.

In a test designed to see whether a model would "cheat" on extremely difficult or impossible hacking tasks, GPT-5.6 Sol was more likely to take forbidden shortcuts, while Astra did not, while still solving some tasks legally.

OpenAI also said that Astra successfully broke through the hardened browser sandbox and executed commands on the host computer; in addition, it discovered and combined multiple vulnerabilities in the operating system to gain root privileges.

The company subsequently delayed the development of some Astra features while adding security safeguards and plans to initially open its most advanced cybersecurity capabilities to only selected testers.

This capability is particularly relevant to the cryptocurrency space, as a software bug can be turned into real profits within minutes. According to reports, an analysis in June this year pointed out that increasingly powerful AI models can compress the process of searching code, discovering misconfigurations, and assembling attacks from days or weeks to machine-speed operations.

At the time, security researchers said the bigger change would not necessarily be entirely new attack types, but that the speed at which existing weaknesses would be found and exploited would increase significantly.

This development also shows that cutting-edge models are moving beyond "answering questions" and "writing code." In July this year, an AI system called Claude Fable 5 helped solve an 87-year-old mathematical puzzle.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet