Live markets
BTC ETH SOL BNB XRP DOGE
View all markets

OpenAI Built a Model That Says Yes to Hacking Requests, Then Delayed the One That Said Yes Too Well

OpenAI Built a Model That Says Yes to Hacking Requests, Then Delayed the One That Said Yes Too Well

Ask a frontier model to build an exploit chain and it refuses. That is the design.

OpenAI has now shipped a model that answers. GPT-5.6-Cyber completes 95% of requests on an internal advanced cybersecurity evaluation.

The comparison numbers are the story. GPT-5.6 Sol, the general model underneath it, completes 1.5%.

What Was Announced

OpenAI expanded Daybreak, the cybersecurity program it launched in June 2026, splitting it into two access tiers.

Daybreak Blue provides GPT-5.6 Sol with system-level cybersecurity guardrails removed. It is positioned as the entry point for most defenders, covering vulnerability discovery, secure code review, malware analysis, incident response and patch validation.

Daybreak Red provides GPT-5.6-Cyber, purpose-trained for authorized vulnerability research, exploit validation and security testing.

The completion rates across those tiers are not close. Blue sits at 2%. Red sits at 95%.

That gap makes clear this is not a renamed existing model. OpenAI changed both the training and the refusal behavior for a narrow, vetted group.

TierModelAdvanced task completion
Standard accessGPT-5.6 Sol1.5%
Daybreak BlueGPT-5.6 Sol, guardrails removed2%
Daybreak RedGPT-5.6-Cyber95%

The Astra Detail Most Coverage Buried

This announcement landed days after OpenAI said it was delaying the release of Astra, its next major model, because the model reached critical hacking abilities during safety testing.

Optimisus covered Astra when it published Lean proofs for ten open mathematics problems. At that point the open question was what the model could do beyond mathematics.

The answer appears to be enough to trigger the top tier of OpenAI’s own Preparedness Framework.

GPT-5.6-Cyber, by contrast, was rated High for cybersecurity capability but did not reach Critical. So the model OpenAI is deliberately handing to offensive security researchers is the less capable of the two.

That framing is worth sitting with. A purpose-built, optimized cyber model falls short of a general model that was not designed for the task.

What It Has Actually Found

OpenAI says GPT-5.6-Cyber has been used in real vulnerability research, including previously unknown flaws in Chrome’s V8 JavaScript engine.

Reported results include two chainable zero-days in V8 and more than 400 escalation issues in a kernel. OpenAI says it is working with Daybreak partners and the open-source community to disclose and fix them.

These are vendor-reported figures from an internal program with no external audit. Treat them as claims about capability rather than verified counts.

The operational consequence is real regardless. If a commercial model can chain zero-days in a browser engine, the window between vulnerability discovery and exploitation shrinks for everyone.

Why This Matters for Crypto Specifically

Smart contracts are code, and exploits against them are the most consequential attack surface in this industry.

The 1inch supply chain compromise, which Optimisus covered when the protocol was hit through its dependency chain, is the pattern this technology accelerates on both sides.

Automated auditing is already a live category. Optimisus reported on an AI audit firm benchmarking against OpenAI’s own smart contract exploit evaluation.

The asymmetry is uncomfortable. Defenders need approval, vetting and hardware keys. Attackers need an unaligned open-weight model, and frontier-scale open weights are now shipping regularly.

The Access Controls

Access is limited to approved defenders with additional monitoring for higher-risk work. Hardware key requirements come into force from September 1.

OpenAI expanded commercial use as well, allowing Accenture, IBM, CrowdStrike, Cisco and Palo Alto Networks to build the models into security products and managed services. Cloudflare has said it intends to pair Daybreak capabilities with its network.

OpenAI recommends Blue for most defenders and describes Red as demanding a more rigorous operating model, precisely because its value comes from answering requests other systems decline.

For any organization considering it, sandboxing, scoped permissions, hardware-backed accounts, action review and documented authorization all need to exist before rollout rather than after.

The Objection Already Surfacing

Vetted access sounds tidy until the vetting misfires.

At least one security researcher working on Bitcoin codebases reported being blocked from continuing analysis on code he had already responsibly disclosed against, shortly after integrating with the program.

That is one account rather than a pattern. But it points at the structural problem with governed access. The same gate that keeps attackers out also decides which defenders count, and that decision sits with a private company.

The Honest Read

OpenAI’s stated reasoning is about timing. Attackers will eventually run AI-driven attacks at speed and scale, possibly autonomously, and defenders have a narrowing window to prepare.

That argument is coherent. It also amounts to a lab accelerating a capability because it expects the capability to arrive anyway, which is a bet rather than a certainty.

The practical takeaway for organizations holding digital assets has nothing to do with which AI tool to buy. If discovery-to-exploitation windows are compressing, patch cadence is the variable that matters.

Anyone running quarterly update cycles on internet-facing systems should revisit that schedule before shopping for anything else.

Sources

Optimisus covers crypto and technology news for readers who want the detail behind the headline.