Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Register
Metaverse Media Group
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
Metaverse Media Group

OpenAI’s GPT-6 Astra hallucinates less but remains vulnerable to hidden prompt injections

OpenAI’s GPT-6 Astra hallucinates less but remains vulnerable to hidden prompt injections

The Decoderby The Decoder
4 September 2026
OpenAI’s GPT-6 Astra hallucinates less than its predecessor and blocks 99.99 percent of direct prompt injections. But when attacks are hidden inside documents the AI reads, the model still gets cracked in 8.5 percent of scenarios. Claude Opus 5 does better at 4.8 percent. For autonomous AI agents handling real data, those numbers still seem high. The article OpenAI’s GPT-6 Astra hallucinates less but remains vulnerable to hidden prompt injections appeared first on The Decoder….


Matthias Bastian


Sep 4, 2026

Image description

Sora prompted by THE DECODER

Key Points

  • OpenAI’s new model GPT-6 Astra hallucinates less than its predecessor GPT-5.6 Sol and blocks 99.99 percent of direct prompt injection attacks.
  • Astra also resists jailbreaks more effectively, but persistent attackers can still get a problematic response about one in three tries over multiple conversation rounds.
  • For indirect prompt injections hidden inside documents the AI reads, Astra’s failure rate dropped from 27 percent to 8.5 percent. That’s a big improvement, but it’s still high.

OpenAI’s new model, GPT-6 Astra, produces fewer hallucinations and blocks prompt injection attacks more effectively than its predecessors. But it still isn’t reliable enough for truly secure AI agent deployments.

The new Astra model makes far fewer factual errors than its predecessor, GPT-5.6 Sol, according to OpenAI’s system card. OpenAI tested it against ChatGPT conversations that users had flagged for wrong answers, meaning these were particularly error-prone cases whose failure rates shouldn’t be taken as typical for everyday use. Astra reproduced these reported errors much less often, with the biggest gains showing up at low latency settings and lower reasoning levels.

GPT-6 Astra (pink) hallucinates less than the GPT-5 models across all latency settings. | Image: OpenAI

For direct prompt injections, where users try to manipulate the model through their own prompts, Astra hits a near-perfect 99.99 percent defense rate. OpenAI credits its GPT-Red method for this, which uses an automated attacker to harden the model during training.

Jailbreak resistance looks similar. Against a fixed dataset of known attacks trying to extract harmful responses about biology, violence, and cybersecurity, Astra refuses to help in 91.5 to 98.3 percent of cases.

When attackers adapt their strategy over multiple conversation rounds, Astra’s defense rate drops to about 67 percent, meaning persistent adversaries can coax out at least one problematic response roughly one in three tries. Predecessor models scored just under 50 percent on the same test. OpenAI notes that these tests ran on the bare model without the production safety layers like classifiers that ship with the actual product.

Hidden prompt injections remain a real security problem

Astra makes progress on indirect prompt injections, where an attack is buried inside a document the AI reads. External testing by security firm Gray Swan, using 1,810 curated attacks from their IPI Arena, found that with 15 attempts per scenario, Astra was cracked at least once 8.5 percent of the time. GPT-5.6 Sol failed 27 percent of the time. Claude Opus 5 did better at 4.8 percent in the same evaluation, but it wasn’t immune either.

Attack success rates for indirect prompt injections according to Gray Swan’s IPI Arena. | Image: OpenAI

The numbers in Gray Swan’s combined Q1 and Q2 test actually went up compared to earlier results. Anthropic previously reported only a two percent attack success rate based on the easier Q1 test alone, and GPT-5.6 Sol scored just 20 percent there too. Anthropic also ran all models with extended reasoning turned on, which, alongside the broader test scope, could explain the gap.

Even though these are curated, hand-picked attacks, the success rates should worry any enterprise security team. Astra can be tricked through injected instructions in roughly one out of every twelve scenarios. Opus 5 holds up better, but it still fails about one in twenty-one. And the risk is growing. AI agents are increasingly writing code, operating tools, and controlling computers on their own, which is what Gray Swan tested. These agents are also being built to run around the clock and at scale, with reading and processing documents as one of their core jobs.

AI News Without the Hype – Curated by Humans

Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive “AI Radar” frontier report six times a year, full archive access, and access to our comment section.


Subscribe now

Read the full article on The-Decoder.com
in AI
Reading Time: 4 mins read
0
0
21
VIEWS
Share on TwitterShare on Facebook

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now
ADVERTISEMENT

Related Posts

The Trump White House’s fetish for gamer culture has moved up a level with new arcade
AI

The Trump White House’s fetish for gamer culture has moved up a level with new arcade

2 hours ago
23
OpenAI’s Astra Becomes Its First AI Model With ‘Critical’ Hacking Abilities
AI

OpenAI Agents Hack German Website to Share Rule-Breaking Tactics: Report

3 hours ago
21
Bitcoin Slides as Blowout Jobs Report Revives Fed Hike Odds
AI

Bitcoin Slides as Blowout Jobs Report Revives Fed Hike Odds

3 hours ago
23

Comments

Please login to join discussion
ADVERTISEMENT

Latest News

  • All
  • Crypto
  • NFTs
  • Technology
  • Business
Sheriffs Go Neutral on CLARITY Act, Easing Pressure on Senate Vote
Crypto

Sheriffs Go Neutral on CLARITY Act, Easing Pressure on Senate Vote

Bitcoin.com News
by Bitcoin.com News
13 minutes ago
22
Bitcoin Price Rally Collapse Wipes Out $295M in Long Positions
Crypto

Bitcoin Price Rally Collapse Wipes Out $295M in Long Positions

Bitcoin.com News
by Bitcoin.com News
1 hour ago
23
OpenAI’s GPT-6 Astra hallucinates less but remains vulnerable to hidden prompt injections
AI

OpenAI’s GPT-6 Astra hallucinates less but remains vulnerable to hidden prompt injections

The Decoder
by The Decoder
1 hour ago
21
A16z-Backed OpenReserve Gets Approval for Full-Service National Bank
Crypto

A16z-Backed OpenReserve Gets Approval for Full-Service National Bank

Decrypt
by Decrypt
1 hour ago
23
Zcash Hits Highest Price in Nearly a Decade, Crushing Short Bets
Crypto

Zcash Hits Highest Price in Nearly a Decade, Crushing Short Bets

Decrypt
by Decrypt
2 hours ago
22
Bitcoin ETFs Pull in $731M as Bitcoin Price Breaks Above $80K
Crypto

Bitcoin ETFs Pull in $731M as Bitcoin Price Breaks Above $80K

Bitcoin.com News
by Bitcoin.com News
2 hours ago
22
Load More
Next Post
Bitcoin Price Rally Collapse Wipes Out $295M in Long Positions

Bitcoin Price Rally Collapse Wipes Out $295M in Long Positions

ADVERTISEMENT

Follow Us

Categories

  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
Subscribe to our Newsletter

© 2022 Metaverse Media Group – The Metaverse Mecca

Privacy and Cookie Policy | Sitemap

Welcome Back!

Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Sign Up
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Subscribe to our newsletter

Get the latest news & win monthly prizes

Subscribe to our newsletter

For the Latest News and Monthly Prize Giveaways

Join Now
Join Now