Skip to main content

LLM Security Rankings

Which LLM is the most vulnerable? View the stats from the largest researcher-validated exploit feed on the internet. 0DIN continuously red-teams production LLMs and publishes the results publicly. Every score reflects real attack attempts, not self-reported safety claims.

Live data • Last updated about 15 hours ago • 48 scans across 23 models

The five most jailbroken model families over the last six months, ranked by susceptibility to known vulnerability probes.

  • 1 Meta logo Scout
  • 2 Meta logo Maverick
  • 3 Alibaba logo Qwen
  • 4 OpenAI logo GPT
  • 5 Twitter / X logo Grok

Get monthly LLM
rankings in your inbox

Comprehensive security rankings

Every frontier and open model, scored against researcher-validated exploits. Sort by risk, filter by vendor, and find the models your security team needs to watch most.

Live data • Last updated about 15 hours ago • 48 scans across 23 models
# Model Risk ASR% Successful attacks
1
Meta logo LLaMa 4 Scout
Critical
62%
864 of 1,385 probes
2
Meta logo LLaMa 4 Maverick
High
46%
639 of 1,385 probes
3
OpenAI logo GPT-5.4
High
36%
492 of 1,385 probes
4
OpenAI logo GPT-5.2
High
34%
477 of 1,385 probes
5
Twitter / X logo Grok 4.2
High
34%
465 of 1,385 probes

Head-to-Head
LLM Comparison

Compare the security of any two AI models, side by side.

VS
Model

Attack success rate over time

Attack Success Rate
Successful attacks

Distinct high ASR vulnerabilities (over 80% attack success across recent scans) each model is susceptible to, and the ones they share

0
only
0
shared
0
only

Human-Powered AI Security Scoring

Our security ratings come from real-world attacks discovered by a global community of security researchers, not synthetic or auto-generated benchmarks. Every probe is a human-discovered exploit, rigorously validated before it counts toward a score.

Attack success rate (ASR)

(Average across scanned models)

Attack Success Rate

Low Risk Moderate Risk High Risk Critical Risk

The average AI model fails 1 in 5 attacks, meaning attackers succeed 18.3% of the time across all scanned production models. A higher Attack Success Rate (ASR) means a model is more easily jailbroken and at greater security risk.

Models scanned
23
Number of unique probes
1,697
Avg successful attacks
285.5
Active researchers
2,184
Submissions rejected
82%
More on our research methods

How does your
LLM rank?