动察 Beating AI Flash: Boris Cherny, head of Claude Code, posted that GPT-6 Astra's prompt injection defenses are now "about the same" as Gemini Flash and Claude Opus 4.8, while also praising his own Claude model for having "practically solved" the issue about two months ago. Prompt injection involves hiding malicious instructions in web pages, documents, and other content to trick agents into leaking data or executing dangerous operations.
Boris also stated that publicly evaluating and calling out other labs is a good way to push them toward training safer models, adding, "We'll keep doing this until other labs take safety more seriously."
The post was quickly countered by an X Community Note. Independent evaluations from Gray Swan showed that no tested model is fully immune to prompt injection, with Claude also exhibiting successful attack cases. Another security researcher used a specially crafted webpage to attack Claude Code Opus 5 Auto Mode, achieving a 60%–80% success rate in small-scale tests.
Thibault Sottiaux, OpenAI's head of core products, then directly mirrored Boris's phrasing in a rebuttal. He said he was also glad to see Claude Code's new background computer operation finally catching up to Codex, "and it's our May version from this year."
Boris later acknowledged that his original post was "more passive-aggressive than intended," emphasizing that he genuinely meant to recognize Astra's progress. He also clarified that his claim about prompt injection being "solved" referred to the product-level effect of combining the Claude model, injection detection mechanisms, and Auto Mode, not that the model itself is inherently immune.

