OpenAI's Cybersecurity Model Just Outperformed Google's $10,000 Bounty Hunters

When the Robot Finds Bugs Faster Than the Professionals
OpenAI just deployed a model that found two previously unreported vulnerabilities in V8—the JavaScript engine powering Chrome—that Google has been paying hackers $10,000 per exploit to discover since 2023. Google patched the flaws before OpenAI even announced the model publicly. Oh, and GPT-5.6-Cyber found over 400 more vulnerabilities in an operating system kernel as a side project.
This isn't GPT-5.6 doing party tricks. This is a specialized cybersecurity model that OpenAI is keeping on the tightest leash we've seen yet.
TL;DR
OpenAI's GPT-5.6-Cyber model discovered two unreported V8 JavaScript engine vulnerabilities worth $10,000 each from Google's bug bounty program, plus 400+ additional kernel vulnerabilities. OpenAI has restricted GPT-5.6-Cyber to the highest tier of its Daybreak early access program because the model answers 95% of exploit-building requests, compared to 98.5% refusal rate for standard GPT-5.6 Sol. The defender's advantage exists only as long as OpenAI remains the sole provider of cyber-capable AI models.
GPT-5.6-Cyber Outperforms Human Bug Bounty Hunters
OpenAI's GPT-5.6-Cyber model identified two previously unknown security vulnerabilities in V8, the JavaScript engine that powers Google Chrome. Google has operated a bug bounty program since 2023 that pays security researchers $10,000 per V8 exploit discovery. Google patched both vulnerabilities discovered by GPT-5.6-Cyber before OpenAI's public model announcement.
Key takeaway: GPT-5.6-Cyber successfully competed with professional security researchers who have financial incentive to find the same vulnerabilities, suggesting AI models can now match or exceed human capability in vulnerability discovery.
OpenAI Implements Two-Tier Access Control on August 10th
OpenAI split its Daybreak early access program into two tiers on August 10th. Only the strictest tier receives access to GPT-5.6-Cyber. Standard GPT-5.6 Sol refuses 98.5% of requests to help build exploits. GPT-5.6-Cyber answers 95% of exploit-building requests—the opposite behavior profile. OpenAI designed GPT-5.6-Cyber to think like an attacker to find vulnerabilities before malicious actors do.
Technical Details: V8 Compiler Optimization Vulnerability
The V8 exploit chain discovered by GPT-5.6-Cyber involves a compiler optimization bug that allows array indices to exceed their boundaries, breaking out of the heap sandbox. This vulnerability type could allow a malicious website to access saved passwords and active banking sessions. The vulnerability remained undetected despite Google's standing $10,000 bug bounty, demonstrating the difficulty of manual vulnerability discovery.
Key takeaway: GPT-5.6-Cyber identified a heap sandbox escape vulnerability in V8's compiler optimization that could enable credential theft—a bug class that evaded human security researchers despite financial incentives.
Cost Economics of AI-Driven Vulnerability Discovery
Human security researchers require rest periods and eventually move to new targets. AI models like GPT-5.6-Cyber can analyze codebases continuously for 24 hours per day, limited only by compute costs. The cost-per-vulnerability discovery has dropped significantly with AI model deployment.
GPT-5.6-Cyber functions identically whether operated by security teams or threat actors. OpenAI's approval-only distribution model for GPT-5.6-Cyber acknowledges this dual-use reality. Multiple AI labs are developing specialized cybersecurity models, and not all labs will implement access controls as restrictive as OpenAI's Daybreak program.
Defender's First-Mover Advantage Is Temporary
Defenders currently hold first-mover advantage. OpenAI provided the two V8 vulnerabilities to Google before releasing GPT-5.6-Cyber publicly. This advantage window shrinks with each competing cyber-capable model released by other AI labs. Coordination becomes exponentially harder when multiple labs operate cyber-capable models simultaneously.
The 400+ kernel vulnerabilities found by GPT-5.6-Cyber in a single analysis pass suggest critical infrastructure contains a massive backlog of undiscovered security flaws. The current race pits AI-assisted security teams finding and patching vulnerabilities against adversaries deploying their own models to discover exploits first.
Key takeaway: OpenAI's early disclosure of V8 vulnerabilities to Google demonstrates the defender's advantage, but this advantage only exists while OpenAI remains the sole provider of cyber-capable AI models.
Access Control Questions for Cyber-Capable AI Models
OpenAI's hyper-restricted access model for GPT-5.6-Cyber raises questions about whether cyber-capable AI tools should exist at all, and if they exist, who should control access decisions.
The Daybreak dual-tier system implemented on August 10th indicates OpenAI believes very few people should access GPT-5.6-Cyber, with extensive vetting required. This approach only succeeds if every AI lab building similar capabilities implements identical restrictions. The history of security tool distribution suggests uniform restriction agreements are unlikely.
Bottom Line: Defensive Advantage Depends on Access Monopoly
OpenAI built GPT-5.6-Cyber, a model that outperforms professional bug bounty hunters at finding security vulnerabilities, then immediately locked GPT-5.6-Cyber behind the most restrictive access controls OpenAI has ever implemented. GPT-5.6-Cyber represents the first clear example of an AI capability where wide deployment makes everyone less safe. Restrictive access only provides defensive advantage if OpenAI remains the sole provider of cyber-capable AI models. The defensive advantage evaporates when a less cautious lab ships a competing model or someone leaks model weights. The clock is ticking on how long defenders can maintain their current advantage.
Frequently Asked
Can I get access to OpenAI's cybersecurity model?
No, unless you're part of OpenAI's restricted Daybreak program and meet the criteria for the highest security tier. OpenAI is limiting access to personally approved defenders due to the model's ability to generate working exploits.
How do AI models find software vulnerabilities?
AI models analyze code to identify patterns that lead to security flaws, test edge cases at scale, and reason about how different code components interact in ways that could be exploited—similar to how human security researchers work, but without needing sleep or breaks.
Will other AI labs release similar cybersecurity models?
Almost certainly. Multiple labs are working on specialized capabilities, and not all will adopt OpenAI's restrictive distribution approach. This creates a race between defenders getting access to these tools and threat actors developing their own versions.
What do the AIs actually think?
Ask GPT, Claude, Gemini and more about this topic simultaneously — and get a Consensus Score showing how much they agree.
Ask the AIs: “OpenAI's Cybersecurity Model Just Outperformed Google's $…” →