Astra and the next cyberattack wave: why the economics are changing
Axyom's Marc Torrents on why Astra's reverse-engineering results could expand agent-driven cyberattacks from Oct 2026 to Mar 2027.
Research cutoff: 7 September 2026
On September 4, I shared a number from Resilience’s midyear cyber risk report: zero incurred losses in its H1 2026 portfolio attributable to prompt injection, model exploitation or agentic AI misuse. Phishing, social engineering and transfer fraud were associated with 85.3% of incurred losses. Resilience’s report announcement.
I also wrote that I expected the AI-native wave to become significant. That forecast deserves an explanation, especially now that Astra offers fresh evidence about what agents can do. My earlier LinkedIn post.
The connection is economic. When understanding software and executing technical work require less human effort, more targets can become worth investigating. Our hypothesis at Axyom is that October 2026 to March 2027 could bring an appreciable expansion in the use of agents to perform technical work in real attack campaigns.
That window is our forecast, with considerable uncertainty. We intend to assess it publicly on March 31, 2027, against documented campaigns and evidence of harm.
What Astra changes
On April 6, Sam Altman described a capability that is central to this shift:
“AI will be incredibly good at finding vulnerabilities in software.”
He connected improving coding ability with the ability to identify security weaknesses, and argued that defenders would need to adapt across society. OpenAI Forum, from 13:26.
Astra adds a concrete result. OpenAI reports that it solved 88.0% of SRE-Bench challenges in one attempt and 99.2% within four, compared with 55.9% and 68.7% for GPT-5.6 Sol. The benchmark evaluates reverse engineering of compiled software without access to its source code. OpenAI’s Astra announcement.
Reverse engineering has existed for decades. Analysts inspect executable instructions, observe behavior and reconstruct enough of a program’s logic to understand it. This does not recover the exact original source or imply that encryption has been broken. The potential change is how much expert work an agent can take on.
SRE-Bench’s authors explain why this matters: malware, firmware and proprietary applications are often available only as binaries. Their benchmark contains 262 binary instances derived from 19 privately developed programs. SRE-Bench research paper.
These are developer-reported benchmark results, with a limited set of programs and defined objectives. A high completion rate does not establish a comparable success rate against arbitrary commercial software, and understanding a program does not automatically produce a usable vulnerability.
OpenAI separately classifies Astra at the Critical cybersecurity capability threshold in its own framework. It reports that, with suitable tools and access, the model can discover unknown flaws and develop ways to exploit them without guidance at every step. Its deployed safeguards restrict some advanced cyber tasks. Astra safety overview.
Why the timing matters
Better reverse engineering can reduce the effort spent understanding a target. Agents that use tools and work through multiple steps can then reduce the effort required to act on that understanding. Together, those capabilities could let the same group pursue more investigations, including targets that previously offered too little return for the work involved.
That is our inference from the capabilities being reported. It does not require every attacker to have unrestricted access to Astra; it depends on comparable capabilities becoming accessible and reliable enough to use in repeatable workflows.
Richard Horne, CEO of the UK’s National Cyber Security Centre, captured that economic mechanism in April:
“AI will make it easier, faster and cheaper to discover and exploit weaknesses”
He also stressed that defenders can retain an advantage by improving their security foundations and adopting the technology carefully. Richard Horne, NCSC.
The difficulty is that deploying a fix has organizational dependencies. Someone must know which systems are affected, own the decision, test the update and confirm that it reached production. Discovering weaknesses faster creates pressure on every one of those steps.
Greg Brockman made a related forecast on August 17, describing how attackers’ capabilities could evolve over the coming months as advanced models diffuse. His assessment supports taking a near-term window seriously, but it does not establish our six-month forecast. The Defender’s Window.
Why the earlier zero does not settle the question
The earlier statistic covers a specific insurer’s portfolio, period and loss classification. It cannot establish that the relevant incidents were absent everywhere or that AI played no role in other losses.
There is also a distinction between attacking an AI system and using AI to attack conventional software. A campaign might use an agent to analyze a binary and exploit a flaw, then deploy ransomware. Depending on the reporting method, it could still appear under vulnerability exploitation or ransomware, with the agent’s contribution recorded separately or remaining unknown.
Our expectation therefore concerns how attacks are performed. We cannot infer a future percentage in Resilience’s AI-specific loss category from Astra’s benchmark scores.
Dario Amodei has expressed a stronger expectation about the direction of travel:
“I expect AI-led cyberattacks to become a serious and unprecedented threat to the integrity of computer systems around the world”
In the same essay, he acknowledges the possibility that defense could keep pace or move ahead with sufficient investment. His statement is a forecast, and the outcome remains open. The Adolescence of Technology.
A forecast we can revisit
There are already published examples. In July, Sysdig reported JADEPUFFER, an extortion operation whose technical execution it assessed to be agent-driven. The researchers based that assessment on observed behavior, including rapid adaptation after failed steps. This gives us a starting point for evaluating expansion. Sysdig’s investigation.
For October 2026 through March 2027, we expect a broader set of documented campaigns in which agents perform substantial technical work. We will look for reports from separate investigative teams, distinct victims, credible evidence of agent execution and verified operational or financial harm. A rising number of announcements alone would not demonstrate the forecast.
Access controls, unreliable agents and faster defensive adoption could slow or limit that expansion. Public disclosure and attribution also introduce delays, so a quiet reporting period would weaken our assessment without proving that no activity occurred.
For a business deciding what to do now, the practical work is clear: identify exposed systems, limit access, assign ownership of remediation and verify that fixes are deployed. The NCSC similarly emphasizes asset inventories, robust access controls, secure configuration and comprehensive logging. NCSC guidance for frontier AI.
The argument for preparation is the shrinking amount of human effort needed to investigate weaknesses. Our earlier emphasis on basic controls still holds; the time available to leave them unfinished may be getting shorter.