
OpenAI's Astra AI can build cyberattacks without human help
OpenAI says its upcoming Astra model can find previously unknown software flaws and turn them into working attacks without a human guiding each step, CoinDesk reports, crossing a cybersecurity threshold that until recently belonged largely to expert hacking teams.
- Astra is the first model OpenAI has classified as having "Critical" cyber capabilities under its Preparedness Framework, the company said in a Tuesday post
- To qualify, a model must find zero-day flaws and build working exploits on hardened real-world systems without human help, or execute an attack from little more than a high-level goal
- In testing, Astra scored 100% on a benchmark for developing exploits from known vulnerabilities and found two previously unknown flaws while building a separate exploit chain
- It broke out of a hardened browser sandbox, executed commands on the host computer, and separately combined multiple operating-system flaws to gain root access
- In a test designed to see whether models would cheat on near-impossible hacking tasks, Astra didn't take prohibited shortcuts, unlike GPT-5.6 Sol, while still legitimately solving some of the tasks
OpenAI has delayed parts of Astra's development to add safeguards and plans to restrict its most advanced cybersecurity abilities to selected testers at first.
That capability lands hardest on crypto, where a software flaw can turn into stolen funds within minutes. CoinDesk reported in June that increasingly capable AI models could compress the work of finding misconfigurations and assembling attacks from days or weeks into machine-speed operations. Security researchers said at the time that the bigger shift wasn't a new class of hack, but how fast existing weaknesses could be found and exploited.
Astra fits a pattern Intokened has been tracking since well before this release: a running tally of documented cases where AI agents already caused real breaches at real companies, and a separate look at how MCP servers widened the attack surface those agents operate through. A model that can independently find and weaponize zero-days doesn't just add to that list. It changes what the fastest possible attack looks like.
None of this is theoretical for crypto specifically. CoinDesk's own June reporting already flagged AI-sped attacks as the live risk, months before Astra earned its Critical rating. OpenAI's safeguards, delayed rollout, and limited tester access are the company's answer to a question it created: what happens once the tool that finds a flaw and the tool that builds the exploit are the same model, running without anyone in the loop.
This piece is informational, not a recommendation to buy, sell, or hold any asset.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
270AI





