Japan-based AI unicorn Sakana AI said on July 21 that it has added a cybersecurity-focused model, Fugu-Cyber, to its Sakana Fugu family and is making it available through a separate API endpoint. In its official blog post, the company said Fugu-Cyber posted an 86.9% success rate on CyberGym and a 72.1% score on CTI-REALM, adding that those results are comparable to specialized frontier security models such as OpenAI’s GPT-5.5-Cyber and Anthropic’s Mythos-Preview.
“Comparable to,” not “better than”
Sakana AI’s wording matters here. The company said the model is “comparable to” those systems, not better than them. The announcement also did not include a ranking table. The source article noted that some Chinese-language media framed the launch as Fugu-Cyber surpassing GPT-5.5-Cyber, but that claim does not appear in Sakana AI’s original statement.
Two benchmarks, two different tasks
CyberGym and CTI-REALM do not measure the same capability.
CyberGym, developed by the University of California, Berkeley, tests whether an AI system can take 188 real open-source projects and 1,507 real vulnerabilities, understand the codebase, trace dependencies, reason about memory behavior, and then produce a proof-of-concept program that triggers the flaw.
CTI-REALM asks a model to read a threat intelligence report and turn it into detection rules that a security team can deploy directly. That process also includes mapping the report to MITRE attack techniques and writing KQL queries. One benchmark is about finding vulnerabilities. The other is about defending against them.
According to the source text, when the CyberGym paper was first published in June 2025, the strongest AI agent at the time had a success rate of just 11.9%. A little over a year later, with the task unchanged, that figure has climbed to 86.9%.
Fugu-Cyber is not a newly trained foundation model
The source article called this the key point. Fugu-Cyber is not a new large model trained from scratch by Sakana AI. It is a cybersecurity-specific version built on top of the broader Sakana Fugu system.
Sakana Fugu is an orchestration framework. In plain terms, it does not solve tasks directly. It acts as a coordinator. Once a request comes in, it dynamically assigns a group of models with different strengths into three roles — Thinker, Worker, and Verifier — and then merges their outputs into a single response exposed through one API.
Sakana AI said the orchestration logic comes from two ICLR 2026 papers, TRINITY and the Conductor. The company also said the underlying third-party models used inside the system are proprietary and are not disclosed by design.
The Fugu lineup now has three versions
The product family currently includes three variants:
- Fugu for general balanced use
- Fugu Ultra for complex reasoning
- Fugu Cyber for cybersecurity tasks
That means the July 21 release is not a new engine. It is the same underlying framework with a security-focused setup and revised usage terms.
Sakana AI’s broader approach
Sakana AI was founded in Tokyo in 2023 by former Google researchers David Ha and Llion Jones. Jones is also one of the co-authors of the 2017 paper “Attention Is All You Need.”
The source article said the company is known for approaches such as evolutionary model merging and AI Scientist, methods described as relying less on brute-force compute scaling. In November last year, Sakana AI raised 32 billion yen, about $200 million, in a Series B round, giving it a post-money valuation of about 432 billion yen, or roughly $2.7 billion.
Its shareholder list includes MUFG, Google, Salesforce Ventures, and In-Q-Tel, the U.S. intelligence community-backed venture firm.
Two pricing tiers, with a jump above 272K tokens
The pricing details were not listed in the launch announcement itself. They appeared instead on the Sakana Fugu product page under the Token Plan.
For Fugu-Cyber, the base tier is priced at $6 per million input tokens, $36 per million output tokens, and $0.6 per million cached input tokens. Once context length exceeds 272K tokens, the service moves to a higher tier: $12 per million input tokens, $54 per million output tokens, and $1.2 per million cached input tokens.
So the widely repeated “$6 to $12 input, $36 to $54 output” description is not a floating range. It is a two-step pricing ladder. The source article said most usage would fall under the $6 input and $36 output tier.
For comparison, Fugu Ultra is priced at $5 per million input tokens and $30 per million output tokens, which puts the cybersecurity version at a 20% premium.
Access is gated by application and manual review
The bigger barrier is not price but access. Fugu-Cyber is application-only. Users must submit a form describing their intended use and provide verified contact information. Sakana AI reviews each case manually and grants access only after approval.
The company also paired the launch with revised terms of use that explicitly ban offensive misuse.

