Subscribe

The trick: Self-Marked

OpenAI just crossed a cybersecurity line no model has crossed before.

Its own timeline shows it saw this coming a month early.

Issue 213 September 20264 receipts3 min

OpenAI's Astra is the first AI model to cross the 'Critical' cybersecurity threshold, a designation that requires independently developing functional zero-day exploits across many hardened systems or running a full cyberattack from a high-level instruction.

Before you read on. Your call?

Astra scored 100% on ExploitBench, chained two real zero-days on an internal test, broke out of a browser sandbox, and strung operating-system flaws into root access.

The twist

OpenAI had already halted the model's development roughly a month before announcing this, built new safety protocols before resuming, disclosed the zero-days to the affected maintainers instead of using them, and is shipping the raw exploit tools to a small vetted alpha group first. The scary headline and the company's own containment plan are the same document.

100%Astra's score on ExploitBench
2zero-day vulnerabilities Astra found and chained on an internal V8 JavaScript test
1stfirst model to cross OpenAI's 'Critical' cybersecurity threshold under the Preparedness Framework
~1 monthroughly how long OpenAI halted Astra's development after detecting the emergent capabilities

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

The trick has a name

We call it Self-Marked: graded by the party that benefits from the grade. You'll see it again. Learn to spot it →

Say this in tomorrow's meeting“Astra hit the scariest tier on OpenAI's own scale. OpenAI's response was to pause it for a month, patch it, and hand the exploit tools to nobody but vetted partners.”

Receipts

  1. Supports decrypt.co: Model hits critical if it can independently develop functional zero-day exploits across many hardened real-world systems
  2. Context fortune.com: only a handful of partners will get access to its most advanced cybersecurity capabilities
  3. Refutes thehackernews.com: Over the past several weeks, we have delayed parts of Astra's development and release while we strengthened and tested protections against cyber misuse
  4. Context thehackernews.com: intends to make its most advanced cybersecurity features available to a group of testers through the Daybreak Blue program

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

This story is a stable, citable object. If you can falsify a verdict,tell us. Corrections are loud here.