Advertisement

OpenAI Backs Cyber Defense With $1 Billion Following Zero-Day AI Breakthrough

OpenAI plans to subsidize $1 billion in access to its cybersecurity models over the next six months, following the disclosure that its Astra system can uncover previously unknown software vulnerabilities and develop working exploits with little or no human guidance.

The company said Thursday that the initiative will help organizations prepare for increasingly sophisticated AI-driven cyberattacks, including zero-day exploits that could be generated by advanced models such as Astra.

A zero-day exploit takes advantage of a software vulnerability that developers have not yet discovered or patched. Attackers can use such weaknesses before a fix becomes available.

OpenAI’s $1 billion commitment is not being established as a conventional grant or investment fund. Instead, the company will offer discounted access to Daybreak, its cybersecurity platform launched earlier this year, along with technical assistance and training.

Daybreak currently has two tiers. Blue uses OpenAI’s standard models for routine defensive security tasks, while Red provides selected organizations with specialized cybersecurity models intended for more sensitive operations. OpenAI said around 2,000 organizations are already using the platform.

The company has identified several sectors as priorities, including water and wastewater infrastructure, electric-grid operators, state and local governments, community and regional banks, nonprofits and open-source software maintainers.

Crypto exchanges, custodians and blockchain networks were not specifically included in the announcement. Still, much of the software supporting the crypto ecosystem is open source and maintained by relatively small teams or volunteer developers.

Projects such as Bitcoin Core and Ethereum clients, along with libraries used by decentralized finance protocols, help secure billions of dollars in digital assets while often relying on limited development resources.

Astra Highlights Growing AI Security Risks

OpenAI’s latest initiative follows the company’s disclosure earlier this week about Astra’s capabilities.

The AI system can reportedly identify previously unknown software flaws and transform those vulnerabilities into functional attacks without requiring a person to direct every stage of the process.

That development marks a notable change in the cybersecurity landscape. Discovering and exploiting sophisticated vulnerabilities has historically required highly skilled security researchers or specialized hacking groups. More capable AI systems could potentially automate significant portions of that process.

Organizations interested in the subsidized Daybreak access can apply through the platform’s website. OpenAI also plans to make the program available in partner countries over the coming weeks.

Crypto Infrastructure Faces AI-Driven Threats

The announcement comes as several incidents have highlighted security weaknesses across crypto and blockchain infrastructure.

In August, a vulnerability in BTCPay Server, an open-source application used by merchants to accept Bitcoin payments, exposed credentials associated with Lightning nodes. Attackers exploited the weakness and drained funds before a patch was issued.

Core Lightning, one of the major software implementations for operating Bitcoin’s Lightning Network, subsequently advised operators to disconnect their machines after AI-generated vulnerability reports uncovered several legitimate security flaws.

Coldcard, a hardware wallet designed to store Bitcoin offline, also released new firmware following a $114 million theft. The company said advanced AI models helped identify separate bugs that were unrelated to the original incident.

These events have intensified concerns that attackers could gain access to more powerful AI-based security tools faster than the developers responsible for protecting critical crypto infrastructure.

More than 30 companies, including Coinbase, Block, BitGo, Blockstream and ARK Invest, have responded by signing an open letter urging AI laboratories to provide security teams with early access to their most capable models.

The companies said AI developers were carefully deciding which organizations could use their strongest systems, while attackers could potentially obtain similar capabilities through other channels.

That creates a growing imbalance for teams maintaining Bitcoin and other open-source infrastructure: they may be responsible for protecting billions of dollars in assets while having access to less powerful AI tools than those potentially available to attackers.

OpenAI’s Daybreak initiative seeks to narrow that gap by giving organizations greater access to advanced AI for defensive cybersecurity work as the technology’s ability to discover and exploit vulnerabilities continues to advance.