OpenAI Launches Patch the Planet for Open-Source Bugs

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI launched Patch the Planet with Trail of Bits, HackerOne, and Calif, offering free security consulting to open-source maintainers — 30+ projects have already joined and hundreds of bugs were uncovered in the first week
- OpenAI released an upgraded GPT-5.5-Cyber model under its limited Trusted Access for Cyber program, scoring 85.6% on the CyberGym benchmark, beating Anthropic's Mythos 5 at 83.8%
- OpenAI shipped its Codex Security scanner as an app plug-in and has subsidized 20 trillion tokens of usage for open-source and private code scanning
- Trail of Bits ran a five-day opening sprint with 25 engineers — roughly a fifth of its entire workforce — working simultaneously with maintainers, funded and supplied with unmetered model access by OpenAI
- Anthropic pulled its Fable 5 and Mythos 5 models off the market earlier this month after Trump administration export controls over fears the model's biological and cybersecurity protections were inadequate
- Patch the Planet participants receive six months of free ChatGPT Pro and six months of Codex Security, plus workflow and infrastructure improvements
- The Five Eyes alliance issued an unusual joint statement warning that frontier AI models are expected to exceed current cyber capability expectations 'in months, not years'
Why it matters: Open-source software underpins much of the internet, and the 30+ volunteer-led projects now enrolled — with hundreds of bugs already found and dozens patched in week one — represent the first material influx of AI-subsidized (20 trillion tokens) defensive resources into a maintainer community drowning in AI-generated slop CVE reports. OpenAI also publicly benchmarked its new model above Anthropic's export-controlled Mythos 5, sharpening the competitive pressure as both firms eye IPOs.




