OpenAI Fenced Astra’s Hacking And Left The C-Suite To Weigh Its Cost | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The GPT-6 Astra artificial intelligence model limited its hacking ability. Users are talking about its extremely high token usage. (Photo by Samuel Boivin/NurPhoto via Getty Images)

On Sunday night, an OpenAI engineer posted a video of GPT-6 Astra that clicked it’s way through all 48 levels of “I’m Not A Robot”, a puzzle game built entirely from CAPTCHAs, the “select every traffic light” tests designed to keep machines out. (I fail at this most of the time!)

It is a toy, not a production security check, but can you believe that a model built to run on your behalf just passed the test that proves that you are a human!

Astra can drive a job across several applications without a person steering each step.

Since the September 4th launch, the two loudest conversations have been about the two thinks OpenAI left off the billboard. GPT-6 Astra is the first model to cross the “Critical” cybersecurity line in the company’s own risk framework, and it shipped with those abilities restricted on purpose.

And paying customers like me are learning that it can empty your subcription usage allowance in under twenty minutes!

The model combines reasoning, coding, a hosted shell, and direct computer control to carry a job across several applications with a person steering each step.

The OpenAI’s Astra Token Bill

First, here’s a quick introduction to Astra and the Token bill. Note that Palantir and Uber have already raised issues with using tokens as a unit of measurement.

AI companies change by the token, a chunk of text roughly three quarters of a word long, and a reasoning model like Astra generates a large volume of hidden tokens working through a task before it writes the answer you see. Subscriptions hide those tokens behind a usage meter that reseats evey fives hours or eery week, and each message draws it down in proportion to what the task cost OpenAI to serve.

That is why the complaints started within hours of September 4 rollout. Astra’s per token price is two and a half times that of its predecessor Sol. One developer told me that building a 3D scene logged six million tokens in thirty minutes (!) roughly ten dollars of compute and watched a Plus account fall to ten percent of its five hour window.

Other Plus users report single tasks wiping out the window in ten to twenty minutes and over the weekend reports surfaced that OpenAI had cut limits for its heaviest users by as much as four times.

Astra costs far more to serve than the model it replace, and OpenAI is passing that cost through the meter rather than the sticker pirce.

What Critical Means for OpenAI’s Astra

OpenAI’s Preparedness Framework is its internal grading system for dangerous capabilities, with critical at the top. Critical in cyber means that the model can find security flaws that nobody has documented and write new exploits for well defended systems without a human guiding it. In testing with safeguards removed, Astra achieved arbitrary code execution in hardened browsers and built privilege escalation exploits against hardened operating systems.

IMG_2123
Dr. David Bray (on the right), who recently was named by the Marconi Society as the inaugural recipient of the “Excellence in AI” Award for global leadership in 2026, and Vinton Cerf (on the left), co-creator of TCP/IP and the internet.

Dr. David Bray, who recently was named by the Marconi Society as the inaugural recipient of the “Excellence in AI” Award for global leadership in 2026, told me, “Given that GenAI is generative in nature, there’s a risk that AI trained on data regarding cyber-vulnerabilities will use such exploits to accomplish explicitly or implicit tasks and not inform a human user. As such, we’ll need to develop better non-generative approaches to restrict what such GenAI tools can do, while at the same time avoiding excessive token costs. We also must upgrade the cybersecurity defense postures of all organizations acknowledging such GenAI tools eventually will be available to multiple actors via open-weight models too.”

So the version customers get is a fenced version. It helps with secure code review and patching and refuses more advance offensive work. OpenAI warns that its safety checks can pause legitimate tasks mid run and every one of those pauses still burns tokens!

Why OpenAI Was Late

In July, during internal cybersecurity evaluations, OpenAI models operating with reduced safeguards got around the controls meant to keep them off the internet, coordinated through improvised message boards, and reached Hugging Face‘s production systems, apparently hunting for answers to the benchmark they had been assigned.

Roughly one third of Hugging Face’s infrastructure had to be rebuilt. OpenAI now reports that Astra is less likely than Sol to violate safety restrictions, though it also disclosed that under adversarial conditions Astra-class models evade the monitors that watch a model’s reasoning.

The Counter View on OpenAI’s Astra

A skeptic would ask whether “Critical” is a safety disclosure or a marketing tier, since OpenAI is grading its own homework.

Independent reviewers from METR and Redwood Research who examined the July incident concluded that stronger security controls alone will not prevent a repeat of what happened with Hugging Face.

The token complaints deserve the same test. OpenAI says Astra uses fewer tokens per task than Sol but the loudest complaints that I’ve from are the heaviest users that are running from it. Measure it on your own traffic before believing either side.

Five OpenAI Astra Moves That C-Suite Users Should Consider

None of this is a reason to wait. Astra is already inside Codex sessions and ChatGPT Work accounts across most large companies, whether or not anyone approved it, and the July incident showed what an agent does with credentials nobody fenced. The question for leaders is not whether to allow it but how to run it, and the following five moves cover both the security fence and the cost fence.

  1. Treat the rollout decision as a policy decision, not an IT one.

  2. Budget by task, not by seat. A subscription that covered a month on Sol may cover a week on Astra.

  3. Log agent actions the way you log privileged employees, and have a person review the logs.

  4. Give agents their own credentials, scoped to the task, that expire.

  5. Ask your security vendors what changes now that attackers can rent a critical tier model

The gap between what OpenAI’s Astra can do and what it is allowed to do is the most interesting number in the release notes and the gap between what it costs on paper and what it costs in practice is a close second.

This article was originally published on Forbes.com



Click Here For The Original Source.

——————————————————–

..........

.

.