Astra is OpenAI's first AI model classified as having 'Critical' cyber capabilities under the company's Preparedness Framework. In internal testing it scored 100% on a benchmark for building exploits from known vulnerabilities, discovered two previously unknown flaws while assembling an exploit chain on a separate test, escaped a hardened browser sandbox, and combined multiple operating-system weaknesses to reach root access on a host machine.
Why it matters
The framework reserves its Critical tier for models that can autonomously find zero-day vulnerabilities and develop working exploits across hardened real-world systems, or that can execute an attack from little more than a high-level goal. That bar, until recently, belonged to expert human red teams. OpenAI has delayed parts of Astra's development to add safeguards and will initially gate the most advanced cyber functions behind a small set of selected testers, but the underlying capability threshold has now been publicly documented.
Market impact
The crypto angle is structural. A software flaw in a wallet, bridge, or smart-contract protocol can be converted into cash within minutes, so any tool that compresses the search-find-exploit cycle from days or weeks to machine speed reshapes defender economics. Security researchers have already warned that frontier models compress rather than invent attack paths, turning a labour-bound problem into a compute-bound one. For protocols holding meaningful TVL, the operational read is that automated vulnerability discovery must become table stakes on the defender side before it does on the attacker side.
Frequently asked questions
-
What is OpenAI's Astra model?
Astra is OpenAI's upcoming AI model, the first the company has classified as having 'Critical' cyber capabilities under its Preparedness Framework. It can find zero-day software flaws and build working exploits without step-by-step human guidance.
-
What does OpenAI's 'Critical' cyber rating mean?
Under the Preparedness Framework, a Critical cyber rating means a model can autonomously find previously unknown vulnerabilities and develop working exploits across hardened real-world systems, or run an attack from a high-level goal without human input.
-
How did Astra perform in OpenAI's cyber testing?
Astra scored 100% on a benchmark for building exploits from known flaws. It also found two previously unknown vulnerabilities while assembling an exploit chain on a separate test, escaped a hardened browser sandbox, and chained operating-system weaknesses to reach root access on a host.
-
Why is autonomous AI hacking a risk for crypto?
A software flaw in a wallet, bridge, or smart contract can be converted into cash within minutes. Frontier models compress the search-find-exploit cycle from days or weeks down to machine speed, turning a labour-bound attacker problem into a compute-bound one.
-
Will the public get access to Astra's cyber features?
Not immediately. OpenAI has delayed parts of Astra's development to add safeguards and plans to restrict the model's most advanced cybersecurity capabilities to a small set of selected testers, though the underlying capability threshold has been publicly documented.
CoinDesk