OpenAI launches Patch the Planet to secure open-source against AI bugs
Trail of Bits deploys 25 engineers; hundreds of bugs patched in first week.
OpenAI announced Patch the Planet, a large-scale initiative with security firm Trail of Bits and vulnerability management companies HackerOne and Calif., to help open-source maintainers patch vulnerabilities and strengthen codebases. The program provides individualized support—custom fuzzers, testing infrastructure, code clean-up—to offset the burden of AI-generated “slop” bug reports. In an opening sprint, 25 Trail of Bits engineers worked simultaneously, yielding hundreds of bugs and dozens of patches in the first week. OpenAI is also subsidizing 20 trillion tokens of usage for its Codex Security scanner, available as an app plug-in, for both open-source and private code.
Separately, OpenAI released an upgraded GPT-5.5-Cyber model with improved cybersecurity capabilities, while expanding trusted access for governments and institutions. The announcements come as competitor Anthropic had to pull its Fable 5 and Mythos 5 models off the market after the Trump administration imposed export controls, citing inadequate safeguards on biological and cybersecurity capabilities. OpenAI’s efforts aim to proactively address AI-enabled security risks while helping open-source communities adopt AI tools sustainably.
- Patch the Planet offers free, individualized security consulting to open-source maintainers overwhelmed by AI-generated bug reports.
- Trail of Bits deployed 25 engineers in a five-day sprint, uncovering hundreds of bugs and producing dozens of patches in the first week.
- OpenAI subsidized 20 trillion tokens for its Codex Security scanner and released an improved GPT-5.5-Cyber model.
Why It Matters
Open-source software, critical to the internet, gets resources to fight AI-driven threats, preventing vulnerabilities before exploits emerge.