Israeli Startup Tenzai Tops HackerOne Leaderboard Using Open-Source AI Model
Israeli startup Tenzai topped HackerOne's vulnerability leaderboard using an open-source Chinese AI model, demonstrating advanced autonomous cyber capabilities on live enterprise networks.

An Israeli cybersecurity startup has reached the top spot on a major global bug bounty leaderboard using an open-source model rather than proprietary American AI systems, highlighting a major shift in the accessibility of advanced cyber capabilities.
Autonomous Hacking with Open-Weight Models
Tenzai's autonomous security platform operates as a fully functional hacker, conducting complete attack cycles against applications, APIs, and chatbots, including reconnaissance, vulnerability exploitation, and continuous monitoring. The startup secured first place on the business VDP leaderboard of HackerOne, the world's largest vulnerability coordination platform, for the second consecutive time.
While previous successes relied on closed models from leading American AI labs, this latest achievement was powered by GLM 5.2, an open-weight model from Chinese lab Z.AI that can be downloaded and run on standard hardware. Crucially, this was not a simulation, but a live test involving corporate networks of government agencies and Fortune 500 companies.
"We wanted to see if we could take an open model that anyone can download and make it perform security research at a level that competes with the strongest and most expensive models," said Pavel Gurvich, CEO and co-founder of Tenzai.
Uncovering Complex Enterprise Vulnerabilities
Gurvich shared two notable examples of vulnerabilities discovered by the autonomous system. In one case, the AI identified a call center service and successfully intercepted real-time sales and support calls due to a minor authorization misconfiguration. In a more complex technical scenario, the autonomous hacker examined an analytics service belonging to a major internet organization. Although write operations were completely blocked, the model discovered that the server was connected to auxiliary database clusters that failed to enforce proper permissions, allowing it to bypass restrictions entirely.
Addressing the risk of threat actors adopting similar open tools, Gurvich noted that while attackers are economically motivated, they currently lack the massive infrastructure required to scale such operations against thousands of targets simultaneously. However, he warned that this scenario is rapidly approaching as AI capabilities become increasingly democratized.
The Debate Over AI Guardrails
When asked about the relevance of strict safety guardrails imposed by major AI labs, Gurvich argued that keeping western models locked down to restricted client lists ultimately harms global cybersecurity. Comparing the situation to the debate surrounding the release of the Metasploit penetration testing framework decades ago, he emphasized that empowering defenders with superior automated tools outweighs the risks of potential misuse.
Founded in 2025 by Pavel Gurvich, Ariel Zeitlin, Ofri Ziv, Itamar Tal, and Aner Mazur, Tenzai has raised $75 million in a seed round led by Greylock Partners, Battery Ventures, and Lux Capital.





