OpenAI Unveils Zero-Day Hunting AI as It Pledges $1B to Cybersecurity

OpenAI is committing $1 billion in subsidized access to its cybersecurity models over the next six months after revealing that its Astra system can identify previously unknown software vulnerabilities and develop functional exploits without step-by-step human direction.

The company said Thursday that the initiative is intended to help organizations defend against increasingly capable AI-driven attacks, including potential zero-day exploits produced by future AI systems.

Zero-day vulnerabilities are previously undiscovered software weaknesses that can be exploited before developers have an opportunity to release a fix.

OpenAI’s $1 billion commitment is not a conventional investment fund or grant program. Instead, organizations will receive discounted access to Daybreak, the cybersecurity platform the company launched earlier this year, along with training and technical support.

Daybreak is divided into two tiers. Blue uses OpenAI’s standard models for routine defensive tasks, while Red gives approved organizations access to specialized cybersecurity models for more sensitive operations. According to OpenAI, approximately 2,000 organizations are already using the platform.

The initiative will focus on critical sectors including water and wastewater infrastructure, electric-grid operators, state and local governments, community and regional banks, nonprofits and open-source software maintainers.

Crypto exchanges, custodians and blockchain protocols were not explicitly listed among the priority groups. However, the open-source software supporting much of the crypto ecosystem could benefit from the program. Bitcoin Core, Ethereum clients and libraries used by DeFi applications are often maintained by relatively small teams and volunteer developers despite securing billions of dollars in assets.

Astra Raises New Cybersecurity Concerns

OpenAI’s announcement follows its disclosure earlier this week that Astra can discover previously unknown software flaws and turn them into working attacks without requiring a human to guide each stage.

The capability represents a major development in cybersecurity. Vulnerability discovery and exploitation have traditionally depended heavily on experienced researchers and specialized hacking teams, but increasingly capable AI could automate parts of that process.

Organizations can apply for subsidized Daybreak access through the platform’s website. OpenAI said it also expects to expand the program to partner countries in the coming weeks.

Crypto Sector Faces Growing Security Risks

The initiative arrives as a series of recent incidents has exposed weaknesses in crypto and blockchain infrastructure.

In August, a vulnerability in BTCPay Server, an open-source application used by merchants to accept Bitcoin payments, exposed credentials associated with Lightning nodes. Attackers used the weakness to drain funds before a fix was released.

Core Lightning, one of the major implementations used to operate the Bitcoin Lightning Network, later advised operators to disconnect their systems after AI-generated vulnerability reports identified several genuine flaws.

Coldcard, a hardware wallet designed for offline Bitcoin storage, also released new firmware after a $114 million theft. The company said advanced AI models had helped identify separate bugs that were not connected to the original incident.

The incidents have added urgency to concerns that AI could give attackers increasingly powerful tools while developers protecting critical infrastructure struggle to access comparable technology.

More than 30 companies, including Coinbase, Block, BitGo, Blockstream and ARK Invest, have signed an open letter urging AI laboratories to provide security teams with early access to their most capable models.

The companies said AI labs were carefully evaluating who could access their strongest systems, while attackers could potentially gain access to similar capabilities regardless.

That imbalance could leave teams maintaining Bitcoin and other open-source networks defending billions of dollars with weaker AI tools than those potentially available to their adversaries.

OpenAI’s Daybreak program is designed to narrow that gap by making advanced AI-based cybersecurity tools more accessible to organizations responsible for protecting critical software and infrastructure.