Skip to main content

LLM Security Rankings

Which LLM is the most vulnerable? View the stats from the largest researcher-validated exploit feed on the internet. 0DIN continuously red-teams production LLMs and publishes the results publicly. Every score reflects real attack attempts, not self-reported safety claims.

Live data • Last updated about 18 hours ago • 36 scans across 29 models

The five most jailbroken model families over the last six months, ranked by susceptibility to known vulnerability probes.

  • 1 Twitter / X logo Grok
  • 2 Google logo Flash
  • 3 Anthropic logo Haiku
  • 4 OpenAI logo GPT
  • 5 Anthropic logo Sonnet

Get monthly LLM
rankings in your inbox

Comprehensive security rankings

Every frontier and open model, scored against researcher-validated exploits. Sort by risk, filter by vendor, and find the models your security team needs to watch most.

Live data • Last updated about 18 hours ago • 36 scans across 29 models
# Model Risk ASR% Successful attacks
1
OpenAI logo GPT-5.4
High
36%
492 of 1,385 probes
2
Twitter / X logo Grok 4.20
High
34%
465 of 1,385 probes
3
Google logo Gemini 3.5 Flash
Moderate
18%
309 of 1,683 probes
4
OpenAI logo GPT-5 mini
Moderate
17%
278 of 1,598 probes
5
Anthropic logo Claude 4.5 Haiku
Moderate
14%
187 of 1,385 probes

Head-to-Head
LLM Comparison

Compare the security of any two AI models, side by side.

VS
Model

Attack success rate over time

—
Attack Success Rate
—
—
Successful attacks
—

Distinct high ASR vulnerabilities (over 80% attack success across recent scans) each model is susceptible to, and the ones they share

0
only
0
shared
0
only

Human-Powered AI Security Scoring

Our security ratings come from real-world attacks discovered by a global community of security researchers, not synthetic or auto-generated benchmarks. Every probe is a human-discovered exploit, rigorously validated before it counts toward a score.

Attack success rate (ASR)

(Average across scanned models)

Attack Success Rate

Low Risk Moderate Risk High Risk Critical Risk

The average AI model fails 1 in 15 attacks, meaning attackers succeed 6.5% of the time across all scanned production models. A higher Attack Success Rate (ASR) means a model is more easily jailbroken and at greater security risk.

Models scanned
29
Number of unique probes
1,697
Avg successful attacks
95.1
Active researchers
2,819
Submissions rejected
83%
More on our research methods

How does your
LLM rank?