GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
OpenAI has released GPT-6 Astra, a new AI model that achieved a perfect score on ExploitBench, demonstrating advanced capabilities in exploiting software vulnerabilities. To mitigate potential misuse, OpenAI has implemented safeguards, limiting access to PoC exploit requests and focusing on defensive workflows like vulnerability analysis and malware detection. The company is also launching a $1 billion initiative, Daybreak for Frontline Defenders, to provide AI tools and support to critical infrastructure sectors to bolster their cybersecurity defenses.
OpenAI has officially unveiled GPT-6 Astra, a new AI model described as the "world's most intelligent and aligned model." The development follows OpenAI’s announcement that the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework.
GPT-6 Astra achieved a perfect score of 100% on ExploitBench, significantly surpassing its predecessor, GPT-5.6 Sol, which scored 78.5%. Furthermore, Astra demonstrated substantially higher arbitrary code-execution rates when testing exploit development capabilities using flaws from the previous three months (July-August 2026), including two previously unknown zero-day vulnerabilities in unspecified software.
To address concerns about potential misuse, OpenAI has implemented safeguards, specifically refusing to comply with prompts requesting proof-of-concept (PoC) exploits. The company is rolling out Astra to a limited set of organizations and will eventually make it available to ChatGPT Plus, Pro, Business, and Enterprise users, as well as through OpenAI API, Microsoft Azure, and Amazon Web Services (AWS) Bedrock.
OpenAI is also launching Daybreak for Frontline Defenders, a $1 billion initiative to provide subsidized access to its models, hands-on training, and technical assistance to critical infrastructure sectors, including water systems, electricity providers, state and local governments, banks, non-profits, open-source maintainers, and organizations with limited security resources. A pilot program with the U.S. Multi-State Information Sharing and Analysis Center (MS-ISAC) will equip public sector and water system defenders with Daybreak access, guided training, and hands-on assistance.
OpenAI emphasized that while Astra’s capabilities can assist defenders in identifying weaknesses, they can also be exploited by malicious actors. The company is prioritizing defensive workflows, such as vulnerability and PoC validation, malware analysis, and detection engineering, while implementing stronger model robustness to better tackle jailbreaks and improve its ability to operate within user-defined boundaries, with safety checks occasionally interrupting legitimate work.
