The timing is probably no accident. The warning landed the same day rival Anthropic shipped Claude Fable 5.1 and Mythos 5.1, and the two companies have a habit of dropping announcements right around each other's releases. On X, CEO Sam Altman explained why his company isn't shipping anything new: the team spent the summer "sprinting on safety priorities," Astra "has been done training for a while now," and the models after it are being slowed down on purpose. Users on X read that as an excuse from a company falling behind. According to The Information, Anthropic passed OpenAI on revenue this year.

Two zero-days as a side effect of an evaluation

OpenAI backs up the critical rating with a batch of tests. On ExploitBench, a benchmark that measures how well a model builds exploits from known vulnerabilities, Astra scored full marks. Worried those tasks might have leaked into its training data, the company built an internal follow-up stocked with 20 recently disclosed, high-severity V8 vulnerabilities.

There too, Astra beat its predecessor GPT-5.6 Sol by a wide margin, while burning far fewer tokens. It also found two previously unknown zero-day flaws and chained them into a working exploit. OpenAI says it's now reporting those vulnerabilities to the people responsible for the affected software.