Skip to main content
Live
Main content

OpenAI launches Patch the Planet and a sharper GPT-5.5-Cyber to outflank Anthropic

GPT-5.5-Cyber scores 85.6% on CyberGym, beating Anthropic's Mythos 5, as OpenAI subsidizes open-source bug fixes at scale.

Jaeden Schafer
Editor in Chief · · 5 min read
OpenAI logo

OpenAI on Monday rolled out a coordinated cybersecurity push built around an upgraded GPT-5.5-Cyber checkpoint and a new open-source bug-fixing program called Patch the Planet, founded with Trail of Bits and vulnerability-management partners HackerOne and Calif. The headline number: GPT-5.5-Cyber scored 85.6% on the CyberGym benchmark, edging Anthropic's Mythos 5 at 83.8%. The model remains gated inside OpenAI's Trusted Access for Cyber program and is not getting a public release.

Patch the Planet is the broader bet. More than 30 open-source projects have already joined, and in a five-day opening sprint Trail of Bits put 25 engineers — roughly a fifth of its workforce — on simultaneous maintainer collaborations. The companies say that first week alone produced hundreds of bug discoveries and dozens of landed patches.

The project pairs each participating maintainer with security consulting, custom agent tooling, six months of free ChatGPT Pro, and six months of Codex Security, OpenAI's code-scanning product that has been in research preview since earlier this year. Trail of Bits CEO and cofounder Dan Guido framed the effort as both defensive and reputational for the AI industry.

Key facts

  • 01GPT-5.5-Cyber scored 85.6% on the CyberGym benchmark, beating Anthropic's Mythos 5 at 83.8%.
  • 02Patch the Planet has enrolled 30+ open-source projects and uncovered hundreds of bugs with dozens of patches in its first week.
  • 03Trail of Bits ran a five-day opening sprint with 25 engineers — roughly a fifth of its workforce — across maintainer collaborations.
  • 04OpenAI has subsidized Codex Security scanner usage to the tune of 20 trillion tokens since its research preview.
  • 05Participants receive six months of free ChatGPT Pro and six months of Codex Security alongside infrastructure improvements.

The backdrop is a flood of AI-generated vulnerability reports — the now-familiar "slop CVE" problem — that has buried open-source maintainers operating with almost no budget. Triage time has ballooned as machine-generated findings stack up alongside legitimate disclosures, and many projects have no full-time security staff to sort signal from noise.

Fouad Matin, OpenAI's cyber tech lead, said the goal is to flip that economics. He noted OpenAI has subsidized Codex Security scanner usage on both open-source and private code "to the tune of 20 trillion tokens," a figure that signals how much compute the company is willing to eat to seed adoption.

Matin added that maintainers "do their work out of love of open source, and now they're stuck reviewing slop CVEs." Patch the Planet's pitch is that the same class of models generating the noise can also clear the backlog — if someone covers the token bill and the engineering hours.

Guido emphasized that the model is consultative rather than one-size-fits-all. Roughly half the sprint time went to actual bug-finding, he said, with the other half spent customizing agents to each codebase so maintainers inherit working tooling, not just a patch list. Trail of Bits plans to continue the work long-term on OpenAI funding plus unmetered model access.

The announcement lands in a tense moment for frontier AI cyber capabilities. Earlier this month Anthropic was forced to pull Fable 5 and its Mythos 5 model off the market after the Trump administration imposed export controls, citing concerns that Anthropic's voluntary blocks on advanced biological and cybersecurity capabilities were insufficient. AI Chat Daily covered that crackdown and the marketing tailwind it has given Anthropic among safety-conscious buyers.

frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months … In this environment, cyber resilience is integral.
Five Eyes intelligence alliance, joint statement
Related · from this week
OpenAI sandbox misconfiguration enabled AI-powered hack on Hugging Face
Jaeden Schafer · 5 min read →

On the same day as OpenAI's launch, the Five Eyes intelligence alliance issued an unusual joint statement on AI cyber risk, compressing the threat timeline from years to months and calling cyber resilience integral to the current environment.

There are real questions about how far the model lead actually goes. A 1.8-point gap on a single benchmark is narrow, and CyberGym does not measure the full surface of offensive or defensive work an analyst performs. GPT-5.5-Cyber is also locked behind Trusted Access, meaning independent researchers cannot replicate the score or stress-test the model against novel codebases. And the open-source community has reasons to be wary of free tooling that creates long-term dependence on a single vendor's subsidies.

Still, the strategic logic for OpenAI is clean. With both OpenAI and Anthropic preparing for IPOs, demonstrating that frontier models can defend critical software — not just break it — is becoming a regulatory necessity as much as a product story. Anthropic's forced retreat on Mythos 5 turned export controls into a moat for whoever can ship cyber-capable models under government-acceptable guardrails. OpenAI is moving to claim that ground, and Patch the Planet gives it a concrete public-interest narrative to pair with a benchmark win. The harder test arrives over the next two quarters: whether 20 trillion subsidized tokens actually shrink the maintainer backlog, or whether the slop just gets faster too.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

OpenAI logo
Security

OpenAI sandbox misconfiguration enabled AI-powered hack on Hugging Face

Security researchers say the breach was not a rogue model — it was a containment environment that was never properly isolated from the internet.

Jaeden Schafer5 min read
OpenAI logo
Security

OpenAI and Trail of Bits launch Patch the Planet for open-source security

OpenAI's Codex Security backs human reviewers at Trail of Bits in a direct counter to Anthropic's Mythos.

Jaeden Schafer5 min read
OpenAI gates GPT-5.5 Cyber after mocking Anthropic for doing the same with Mythos
Security

OpenAI gates GPT-5.5 Cyber after mocking Anthropic for doing the same with Mythos

Sam Altman called Anthropic's Mythos rollout 'fear-based marketing.' Now OpenAI is shipping its own cyber tool only to vetted defenders.

Jaeden Schafer4 min read