OpenAI says its upcoming Astra model has become the company’s first AI system to reach its “Critical” cybersecurity capability level, demonstrating that it can identify previously unknown software vulnerabilities and develop exploits without requiring a person to direct every step.
The company said Astra can discover zero-day flaws and transform them into functional attacks against hardened systems, marking a capability that has historically been associated mainly with highly skilled cybersecurity teams.
OpenAI classified Astra as its first model with “Critical” cyber capabilities under its Preparedness Framework in a post published Tuesday.
Under the company’s criteria, an AI system reaches that level if it can independently uncover previously unknown vulnerabilities, create working exploits and deploy them against hardened real-world environments. It can also qualify by turning a broad, high-level objective into a completed cyberattack with minimal human involvement.
During testing, Astra achieved a 100% score on a benchmark measuring its ability to create exploits from known vulnerabilities. In a separate internal evaluation, the model discovered two previously unknown flaws while constructing a chain of exploits.
OpenAI also said Astra managed to escape a hardened browser sandbox and run commands on the underlying host machine. In another test, it identified and linked multiple operating-system vulnerabilities to obtain root-level access.
The company has paused portions of Astra’s development while it strengthens its safety measures. OpenAI said the model’s most advanced cybersecurity capabilities will initially be available only to a limited group of testers.
The development could have major implications for the crypto industry, where a software vulnerability can potentially be converted into financial losses within minutes. Security researchers have warned that increasingly capable AI systems could dramatically shorten the time required to inspect code, identify configuration mistakes and assemble exploits, reducing work that previously took days or weeks to near-machine speed.
The key concern is not necessarily that AI will invent entirely new categories of attacks, but that it could dramatically accelerate the discovery and exploitation of weaknesses that already exist.
Astra’s capabilities also add to broader evidence that frontier AI systems are moving beyond conventional question answering and code generation. Anthropic’s Claude Fable 5, for example, was reported to have helped solve a mathematics problem that had remained unresolved for 87 years in July.

More Stories
Bitcoin and XRP Pull Back as Bearish “Bart Simpson” Pattern Returns
Bitcoin Drops Below $76,500 as Iran Strikes Push Oil Past $93
Liz Truss Warns Bond Market Rout Could Trigger Emergency UK Spending Cuts