OpenAI says its forthcoming Astra model has reached a new benchmark in autonomous cybersecurity, becoming the first system from the company to receive a “Critical” cyber capability rating.
According to OpenAI, Astra can uncover previously unidentified software vulnerabilities, including zero-days, and create functional exploits without requiring a human to guide the process step by step.
The company described Astra as its first model to meet the “Critical” cybersecurity threshold under its Preparedness Framework in a post published Tuesday.
OpenAI’s standard requires a model at this level to independently discover unknown flaws, produce working exploits and use them against hardened real-world systems. Another route to the classification is for the model to take a broad objective and independently plan and carry out an attack.
Astra performed strongly in testing. It recorded a perfect score on a benchmark designed to assess its ability to develop exploits using known vulnerabilities. During a separate internal exercise, it identified two previously unknown vulnerabilities while creating a multi-step exploit chain.
The model also demonstrated the ability to escape a hardened browser sandbox and execute commands on the host machine. In another test, Astra reportedly combined several operating-system vulnerabilities to obtain root-level privileges.
OpenAI has responded by slowing parts of Astra’s development and introducing additional security controls. The company plans to limit access to its most powerful cyber capabilities at launch, making them available only to a select group of testers.
The implications could be particularly significant for the cryptocurrency industry, where vulnerabilities can quickly translate into substantial financial losses. More advanced AI could automate large portions of the process involved in reviewing software, detecting misconfigurations and connecting vulnerabilities into usable attack chains.
Researchers have previously suggested that the biggest shift may not be the emergence of completely new hacking techniques. Instead, AI could make existing weaknesses much faster and easier to identify and exploit, turning tasks that once required days or weeks into processes that can be completed at machine speed.
Astra’s progress is part of a broader trend in which advanced AI systems are increasingly demonstrating capabilities beyond basic question answering and programming assistance. Other frontier models have recently shown progress in areas once considered difficult for automated systems, including complex mathematical problem-solving.































