HomeArticle

Just now, GPT-6 Astra has "crushed" all CAPTCHAs.

鲸选AI2026-09-08 08:00
Nowadays, all websites, big or small, rely on verification codes to distinguish humans from bots during the login process, and this mechanism will become obsolete after tonight.

After the release of GPT-6 Astra, it has set off wave after wave of tremendous shocks, and just now it has easily broken through another human security protection.

Developer Sharif Shameem announced his latest test: GPT-6 Astra successfully cleared the web game "I Am Not a Robot" created by Neal Agarwal, with all 48 levels being various types of CAPTCHAs.

Astra's full clearance of the game also means that GPT-6 Astra has "killed" all CAPTCHAs and obtained the "I am human" certification.

As shown in the demo video, GPT-6 Astra does not merely "answer CAPTCHA images", but operates the browser through Computer Use, identifies screen content, clicks, inputs, drags and handles continuously changing game rules, and finally completes the entire process.

01

All Website Firewalls Are Invalidated

First, let's introduce CAPTCHA, whose full name is: Completely Automated Public Turing test to tell Computers and Humans Apart. It is a CAPTCHA system used by websites to block robots and distinguish between humans and scripts.

The mainstream CAPTCHA abroad is reCAPTCHA developed by Google, while there are many third-party SaaS services in China such as NetEase Yidun. Its main function is to block robots when users log in to the website.

There are 48 levels in total in this CAPTCHA test game. In the past, no AI could make it through all these levels.

Even for ordinary people, it takes 30 to 60 minutes to clear all levels.

The first level is very simple, you only need to check a box. Then the difficulty rises gradually: identify stop signs, find Waldo, draw a perfectly round circle, parallel parking, complete jigsaw puzzles, play whack-a-mole.

The 37th level provides a bunch of real human photos, and you need to pick out the AI-generated faces. This level is equivalent to letting AI catch AI.

The 42nd level sets reverse rules on purpose: you have to actively answer several simple questions incorrectly to prove that you are a human, and the AI has to learn to act stupid.

The 47th level is a rhythm game with an accuracy requirement of 85%, which is widely recognized by the player community as a level that drives most players to quit.

This whole process is roughly as follows: GPT-6 Astra calls its multimodal capability to identify the content in this clearance game. For some levels of line elimination, reasoning process may also be required, then it calls the Computer Use capability to click buttons, drag sliders, and tap the keyboard, finally completing all tests.

After passing the last level, the system will output the "Human Verification" result, and GPT-6 Astra finally obtained the Verified Human certificate.

At present, the difficulty of CAPTCHAs on most human websites does not exceed that of this CAPTCHA system, which means that AI can break through website login at any time.

02

Computer Use Shows Its Full Potential

The core reason why GPT-6 Astra can clear "I Am Not a Robot" is that its Computer Use capability has been greatly improved compared with the previous generation model.

In the OSWorld 2.0 computer use test that tests hands-on capabilities, Astra scored 72.6%, with an average time of about 40 minutes per task, while the previous generation GPT-5.6 Sol scored 65.7% and took 75 minutes. While the capability is improved, the time consumption is reduced by 47%.

It even operates faster than ordinary people clicking the mouse and keyboard. Meanwhile, the context window of this generation has reached 1.05 million tokens. When the task runs to the 40th minute, it still remembers what it was asked to do at the very beginning.

This is the biggest capability improvement of GPT-6 Astra. It does not compete in the fields of Coding and scientific research, but focuses on the capability of invoking Computer Use.

Therefore, after the release of GPT-6 Astra, a large number of cases of AI operating 3D creation software such as Blender have emerged.

Some users ask Astra to open Blender to make 3D games, and watch it adjust scripts, view screenshots, press function keys, and complete the whole process by itself. Ordinary people do not need to spend a lot of time learning professional software like Blender, as GPT-6 Astra can directly operate Blender to generate works like a master.

The most intuitive case I have seen is that a netizen provided Astra with a portrait, and granted Mac computer permissions to it. Then users can watch it use Apple Notes on the Mac, outline the face shape and facial features stroke by stroke, and finally draw the exact same self-portrait.

There is another case where GPT-6 and Fable 5.1 access Canva to create graphics. The operation capability of GPT-6 is far stronger than that of Fable 5.1. At present, its Computer Use capability is indeed unrivaled.

03

AGI Is Truly Approaching

After the release of GPT-6 Astra, many people say that AGI has arrived. This is because compared with other contemporary models, it does show the so-called intelligence emergence.

The most remarkable score on the official report card is ARC-AGI 3, which is as high as 99.9%. This test puts the model in a strange game without any instructions, and asks the model to figure out the rules and clear the level by itself. Astra passes 96% of the levels with fewer steps than humans, and this capability is indeed very impressive.

Coupled with the great improvement of Computer Use capability, it means that both the "brain" and hands-on capabilities of the large model have been greatly enhanced, so Astra was the first to pass the CAPTCHA test among all models.

However, after Astra cleared "I Am Not a Robot", it also made more people realize the severe security risks brought by AI.

OpenAI itself once announced that Astra is the first model that touches the "Critical" cybersecurity risk line.

In its internal test in July this year, several OpenAI research models bypassed the sandbox and connected to the Internet by themselves. The company was worried that the models would cause unexpected problems, so it suspended part of the training and went back to reinforce the isolation environment. It is even uncertain whether Astra had participated in this incident in the internal test at that time.

There are also cases where AI has top-level attack and defense capabilities: Astra once independently discovered two previously unknown zero-day vulnerabilities, and got full marks on the ExploitBench vulnerability exploitation benchmark. Of course, after the official release of Astra, it was clearly stated that such advanced requests will be rejected, and this part of the capability will only be gradually opened to security teams engaged in defense work.

I still remember that at the press conference, Greg Brockman, President of OpenAI, only said one sentence at the end: "Welcome to the AGI era."

There is still controversy over whether Astra has brought AGI, but the impact brought by the CAPTCHA incident is real.

Nowadays, logging in to websites of all sizes relies on CAPTCHAs to distinguish humans from robots, and this mechanism will become obsolete after tonight.

In the future, if websites want to distinguish whether the person on the other side of the screen is a human or an AI, relying only on "checking a box or identifying an image" may no longer be enough.

This article is from the WeChat Official Account "Jingxuan AI", author: Jingxuan AI, published with authorization from 36Kr.