OpenAI’s new model can find 0days on its own—the AI security war is really here
OpenAI has just confirmed that its upcoming Astra has reached the highest level of “Critical Cybersecurity Capability.”
Put simply: in the past, AI mostly helped security teams analyze vulnerabilities. Now, with less human intervention, Astra can find unknown vulnerabilities on its own, chain attacks together, and then develop usable exploitation methods. OpenAI says that in internal evaluations, it even discovered 2 previously unknown zero-day vulnerabilities.
The data is even more direct.
Astra scored 100% on ExploitBench, and compared to GPT-5.6 Sol, it can achieve more complex vulnerability discovery and exploitation using fewer tokens. As a result, OpenAI has paused some development work for several weeks—first upgrading isolation, monitoring, and abuse protections, before preparing to release.
But this isn’t “an AI hacker tool will be released to the masses right away.”
OpenAI has made it clear: Astra will be released soon, but the strongest cybersecurity capabilities will only be made available to a small number of testers and Daybreak Blue defense partners first. The normal public version will face stricter limits.
For Crypto, this is actually more directly relevant than many AI coin news stories.
Exchanges, wallets, cross-chain bridges, and smart contracts are already valuable targets for attackers. If AI begins automatically searching for vulnerabilities, security teams in the future will also have to use AI for automated defense—pushing the entire industry into a stage of “AI attacking AI defenses.”
So the real upside of this news isn’t all AI Tokens.
What’s worth focusing on instead are the real security infrastructure components: smart contract audits, wallet permissions, MPC custody, on-chain monitoring, and Agent security.
Astra demonstrates one thing: AI capabilities have started moving from “able to write code” to “able to autonomously find weaknesses in systems.”
The biggest AI risk for Crypto going forward may not be whether the model can trade, but whether it can find that vulnerability earlier than the security team.
#OpenAI #AI #OpenAI称Astra可自主发现漏洞