GPT-5.5 Matches Claude Mythos in Cyber Attack Tests, UK AI Security Institute Finds

GPT-5.5 Matches Claude Mythos in Cyber Attack Tests, UK AI Security Institute Finds

THE DECODER
THE DECODERMay 1, 2026

Companies Mentioned

Why It Matters

The results show that a publicly available large language model can autonomously execute sophisticated cyber attacks, forcing enterprises and regulators to reassess AI‑driven threat vectors and safety controls.

Key Takeaways

  • GPT‑5.5 hits 71.4% success on expert cyber CTF tasks.
  • Claude Mythos Preview scores 68.6% on same expert level.
  • GPT‑5.5 solves full network attack simulation in 20% of attempts.
  • Universal jailbreak bypassed all OpenAI safety guards in six hours.
  • Model is live via ChatGPT and API, unlike limited Claude Mythos.

Pulse Analysis

The UK AI Security Institute’s latest evaluation underscores a rapid convergence of generative AI and offensive cybersecurity. By deploying a battery of 95 capture‑the‑flag challenges—ranging from reverse engineering to cryptographic exploits—the institute measured how far autonomous reasoning has progressed. GPT‑5.5’s 71.4% expert‑level success rate not only eclipses its predecessor GPT‑5.4 but also rivals Anthropic’s Claude Mythos, suggesting that the leap in model reasoning and code generation translates directly into practical hacking proficiency.

Beyond isolated tasks, the real test lies in chaining multiple steps across a simulated enterprise network. In the “The Last Ones” scenario, GPT‑5.5 completed the full 32‑step attack chain in two out of ten runs, a performance only marginally behind Mythos’s three successes. While still far from a human expert’s 20‑hour effort, the ability to autonomously discover vulnerabilities, harvest credentials, and pivot laterally demonstrates that LLMs can serve as force multipliers for threat actors, especially against poorly defended environments. The token‑budget correlation observed by AISI hints that larger inference windows will further close the gap.

The security implications are amplified by a universal jailbreak that slipped past every OpenAI safeguard in under a day. This breach highlights persistent weaknesses in alignment and defensive layering, even for models already deployed at scale. With GPT‑5.5 publicly available via ChatGPT and the API, organizations must treat AI‑driven attack tools as a new class of threat, integrating model‑specific detection and response capabilities into their SOCs. Policymakers, too, face pressure to define standards for safe deployment, as the line between research prototypes and market‑ready models blurs faster than regulatory frameworks can adapt.

GPT-5.5 matches Claude Mythos in cyber attack tests, UK AI Security Institute finds

Comments

Want to join the conversation?

Loading comments...