LLM Security Rankings
Which LLM is the most vulnerable? View the stats from the largest researcher-validated exploit feed on the internet. 0DIN continuously red-teams production LLMs and publishes the results publicly. Every score reflects real attack attempts, not self-reported safety claims.
The five most jailbroken model families over the last six months, ranked by susceptibility to known vulnerability probes.
-
1
Grok
-
2
GPT
-
3
Flash
-
4
Haiku
-
5
Sonnet
-
1
Twitter / X
-
2
OpenAI
-
3
Google
-
4
Anthropic
Get monthly LLM
rankings in your inbox
Comprehensive security rankings
Every frontier and open model, scored against researcher-validated exploits. Sort by risk, filter by vendor, and find the models your security team needs to watch most.
| # | Model | Risk | ASR% | Successful attacks |
|---|---|---|---|---|
| 1 |
GPT 5.6 Luna
|
High |
|
672 of 1,697 probes |
| 2 |
GPT-5.4
|
High |
|
492 of 1,385 probes |
| 3 |
GPT-5.2
|
High |
|
477 of 1,385 probes |
| 4 |
Grok 4.20
|
High |
|
465 of 1,385 probes |
| 5 |
GPT-5.6 Sol
|
High |
|
538 of 1,697 probes |
Head-to-Head
LLM Comparison
Compare the security of any two AI models, side by side.
Attack success rate over time
Distinct high ASR vulnerabilities (over 80% attack success across recent scans) each model is susceptible to, and the ones they share
Human-Powered AI Security Scoring
Our security ratings come from real-world attacks discovered by a global community of security researchers, not synthetic or auto-generated benchmarks. Every probe is a human-discovered exploit, rigorously validated before it counts toward a score.
Attack success rate (ASR)
(Average across scanned models)
Attack Success Rate
The average AI model fails 1 in 7 attacks, meaning attackers succeed 14.5% of the time across all scanned production models. A higher Attack Success Rate (ASR) means a model is more easily jailbroken and at greater security risk.
- Models scanned
- 23
- Number of unique probes
- 1,697
- Avg successful attacks
- 199.1
- Active researchers
- 2,400
- Submissions rejected
- 82%