AI’s ‘middle class’ has gotten dramatically better at hacking

As AI models continue to advance at breakneck speed, researchers are sounding the alarm about a concerning trend. The “middle class” of smaller AI models, often overlooked in favor of their more powerful and expensive counterparts, is rapidly improving its hacking capabilities. According to new research from XBOW, these mid-tier models are now capable of performing complex tasks with surprising accuracy, posing a significant threat to cybersecurity.

The middle class refers to a group of proprietary and open-source models that have been quietly gaining ground in the world of AI-powered hacking. Models like Z.ai’s GLM-5.2, xAI’s Grok 4.5, Anthropic’s Opus 4.7, Meta’s Muse Spark 1.1, and others are now capable of completing tasks that were previously the domain of more advanced frontier models. This is not just a matter of catching up; these mid-tier models have crossed a critical threshold, providing significant value at a lower cost.

As Albert Ziegler, head of AI at XBOW, explained, “It’s not that they’re catching up to the frontline competitors as such, but rather that they are crossing a certain threshold, which means suddenly they are providing net value at a cheaper price.” This affordability is precisely what makes these models so concerning. With their relatively low costs, users can run them repeatedly on complex tasks, solving challenges that would have been too expensive or time-consuming to tackle with frontier models.

One notable example of this trend is the release of OpenAI’s GPT 5.5, a near-frontier model that has delivered impressive performance in exploitation benchmarks. According to XBOW’s report, GPT 5.5 saw marked improvements over previous middle-class models in exploiting both “white box” and “black box” scenarios, or with and without access to the underlying victim source code. Its “miss rate,” or failure to spot a vulnerability, was significantly lower than its predecessor, GPT 5.

The emergence of GPT 5.5 has changed the practical baseline for what frontier models can do in offensive workflows. However, the performance leap goes deeper than that. GPT 5.5 performed higher in tests without source code access, while GPT 5 heavily leaned on source code. This is significant because it shows that these AI models are becoming increasingly adept at exploiting vulnerabilities without relying on source code.

Another area of concern is the ability of multi-agent swarms to find vulnerabilities in open-source software projects. Research from Anthropic tested two models – Mythos Preview and Opus 4.8 – and found that coordinating agent swarms could identify significantly more vulnerabilities than individual agents working alone. However, this came at a steep cost: millions of tokens were burned through in the process.

The takeaway from these findings is clear: while frontier models may have their advantages, the middle class of AI models is rapidly closing the gap. As these mid-tier models become increasingly capable and affordable, organizations must take steps to protect themselves from the growing threat. This means being aware of the capabilities and limitations of different AI models, as well as investing in robust cybersecurity measures that can keep pace with the evolving threat landscape.

Ultimately, the rise of AI-powered hacking requires a fundamental shift in our approach to cybersecurity. We can no longer rely on traditional methods alone; instead, we must adapt to the new reality of AI-driven threats and develop strategies that account for their unique characteristics. By doing so, we can stay ahead of the curve and protect ourselves against the growing threat posed by these increasingly sophisticated AI models.


Source: CyberScoop — 2026-08-13