Astra reaches critical cybersecurity capability level
Astra has been classified as the first model to reach the Critical cybersecurity capability threshold under its developer’s Preparedness Framework. With suitable tools and access, it can independently find unknown flaws in hardened systems and build working attacks from them. Testing included public benchmarks, a private set of 20 recently disclosed V8 vulnerabilities, and expert assessments of a secured browser and operating system. Astra scored 100% on ExploitBench, used fewer output tokens than GPT-5.6 Sol, and found two previously unknown vulnerabilities during an exploit-chain test. It also demonstrated a browser escape that ran commands on the host and a privilege-escalation chain that gained root access. Development and release were partly delayed while stronger refusal training, misuse controls, and activity monitoring were added. The model is expected to launch soon, but its strongest cyber features will initially be restricted to selected testers and later offered through Daybreak Blue for defensive work.
Why it matters
- —Astra can find previously unknown security flaws and combine them into working attacks with little or no step-by-step human guidance.
- —The designation sets a new safety bar because powerful cyber capabilities could be misused by attackers or produce harm through unauthorized model actions.
- —Restricted access, refusal training and real-time monitoring may become a template for releasing future models with advanced cybersecurity skills.
Key facts
- Astra is the first model designated at the Critical cybersecurity capability level under the Preparedness Framework.
- It scored 100% on ExploitBench, which tests exploit development from known vulnerabilities.
- On an internal test of 20 recent high-severity V8 flaws, Astra achieved higher code-execution rates than GPT-5.6 Sol while using fewer output tokens.
- Astra found two zero-day vulnerabilities during testing and used them in an exploit chain; disclosure to the maintainers is underway.
- Expert tests produced a browser sandbox escape and an operating-system attack that raised access from a normal user to root.
The full text is in the original source. Here we provide a brief summary and key facts.