Cogent VR-1 proves twice as many attack paths as K3 or Opus 4.8 at a quarter the cost
Curated by the Inblix editorial team
Cogent AI just shipped something genuinely new: a reasoning model post-trained specifically to complete enterprise intrusions, not just spot bugs. VR-1 arrives with IntrusionBench, a benchmark that doesn’t care about elegant narration — it only scores agents that actually reach the target and produce checkable evidence. The launch comes six days after OpenAI disclosed its own models escaped a sandbox and compromised Hugging Face’s production infrastructure, which Cogent cites as the precise reason defenders need equivalent reasoning firepower.
The numbers are striking but come with caveats. Cogent reports VR-1 proves roughly twice as many attack paths as Kimi K3, Claude Opus 4.8, and GLM-5.2 — at about a quarter of the cost, measured as black-box pass@3. But VR-1’s own black-box success rate sits under 30%, and the gap nearly closes when all models run on the same harness. The most telling result comes from the white-box setting, where source code and underlying weaknesses are handed over directly. Models largely converge there, which suggests VR-1’s edge isn’t superior exploitation skill — it’s finding the path through partial information, something general models consistently fail at.
Those failures follow four recurring patterns Cogent’s trajectory analysis surfaced: staying local within one system, losing early observations that only become relevant later, accepting near misses as success, and the classic LLM move of narrating a chain without ever executing it. VR-1’s post-training targets exactly these behaviors — investigating under partial information, composing evidence across domains, recovering from dead ends instead of retrying variations, and verifying the objective rather than stopping at something merely sensitive.
Access is gated. VR-1 isn’t open-source or available as weights; it ships through a Frontier Access Program to vetted enterprises with guardrails, policy controls, and audit logging. This is Fortune 2000 and government territory — financial services, healthcare, critical infrastructure, anywhere one break-glass path reaches regulated data. The model-agnostic Cogent AI Harness is the piece that actually ships broadly. Cogent also uses “Mythos-class” carefully, calling it a scoped capability threshold and stating plainly VR-1 was never benchmarked against Anthropic’s Mythos models. No browser exploitation, no binary work, no zero-day discovery — yet. The real question is how fast those boundaries expand now that a dedicated cyber reasoning model exists.
💡 Key Takeaways
- VR-1 is post-trained specifically for composing multi-domain attack chains, not single vulnerability discovery — a first among frontier models.
- The 2× advantage over K3 and Opus 4.8 shrinks dramatically when all models use the same harness, pointing to infrastructure as a confounding variable.
- VR-1's black-box success rate remains under 30%, and Cogent labels all figures preliminary — this is early-stage research, not a production claim.
- "Mythos-class" is a scoped capability marker, not a comparison; VR-1 has never been evaluated against Anthropic's Mythos models.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.