Analysis
OpenAI disclosed that GPT-6 Astra scored 100% on ExploitBench, its internal benchmark for exploit-development capability, up from 78.5% for predecessor model GPT-5.6 Sol, according to The Hacker News -- the clearest quantified jump yet behind the "Critical" cybersecurity threshold Pulse previously covered when Astra launched on September 3.
What's new since that launch coverage is the specific number and the safeguard OpenAI is pairing with it: the company says it is actively blocking direct requests for proof-of-concept exploit code, even from the small set of vetted organizations that currently have access to the model. That's a narrower, more concrete claim than the original "Critical threshold" framing, which described a capability tier without disclosing exactly how far past the line Astra had moved.
A perfect benchmark score is also a benchmark-design question as much as a capability one: ExploitBench is OpenAI's own test, run without production safeguards to measure the model's raw capability, not what a real user could extract from the shipped, safeguarded version. The gap between raw capability and what actually gets through OpenAI's classifiers in production is the number that matters most for security teams, and it's the one OpenAI hasn't published.