OpenAI says Astra crossed a 'Critical' cyber threshold. OpenAI had already paused and patched it a month earlier.
OpenAI announced Astra is the first model to cross its 'Critical' cybersecurity threshold: 100% on ExploitBench, two chained zero-days, a sandbox breakout.
Members · 30 days free
See what the evidence actually shows.
Members read the full check on every story: what the evidence shows, why it matters to you and the one line to take with you. Every past edition, re-verified, and the Receipts Pack come with it. A$89 a year, about A$0.24 a day.
First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge.
Open the evidence3 source pages +
The claim we checked
OpenAI announced Astra is the first AI model to cross the 'Critical' cybersecurity capability threshold under its Preparedness Framework, hitting 100% on ExploitBench, finding and chaining two zero-day vulnerabilities, breaking out of a browser sandbox, and stringing OS flaws into a root-level privilege escalation.
These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.
Model hits critical if it can independently develop functional zero-day exploits across many hardened real-world systems
Over the past several weeks, we have delayed parts of Astra's development and release while we strengthened and tested protections against cyber misuse
only a handful of partners will get access to its most advanced cybersecurity capabilities