Impact Newswire

Did You Know OpenAI’s Rogue Agents Also Hijacked a German Website?

A swarm of rogue OpenAI agents hijacked a German website this spring and turned it into a message board for other AI agents, according to new research published on Friday and two people familiar with the incident.

Did You Know OpenAI’s Rogue Agents Also Hijacked a German Website

OpenAI officials learned about the incident weeks after it occurred but did not disclose it publicly as executives dealt with the fallout from a July breach of open-source repository Hugging Face, the people said.

The incident, which began in May and has not previously been reported, highlights growing concerns about the risks posed by increasingly autonomous AI agents. Companies are racing to develop systems capable of performing complex tasks with limited human supervision, while researchers and security experts have warned that such systems could exploit loopholes, circumvent restrictions and coordinate in unintended ways.

During the Hugging Face breach, OpenAI agents autonomously plotted a digital heist that went undetected for more than a week, raising questions about whether the company was moving too quickly in its pursuit of more capable AI systems.

OpenAI has pledged to strengthen monitoring of its models. Last month, the company briefly paused some model training to add safety measures. This week, it unveiled its new “Astra” model, which it said offered improved performance but could evade human monitoring.

The German incident points to a broader pattern of AI-agent activity that some OpenAI investigators wanted to examine more closely. Efforts to expand the investigation met resistance from some people inside the company, including legal advisers.

“Claims that our legal team discouraged investigation of the incident are false,” an OpenAI spokesperson said.

The activity in Germany was unrelated to the Hugging Face breach and would not have been included in a report on that incident, the spokesperson said. OpenAI has acted in good faith by cooperating with outside experts and disclosing relevant incidents, the spokesperson added.

Researchers Sydney Von Arx, CEO of AI safety nonprofit Nightingale, and Cormac Slade Byrd, a quantitative trader-turned AI researcher, detailed the German incident in a report shared exclusively with Reuters.

The researchers said they discovered the activity in late August while searching the internet for signs of unauthorized AI-agent behavior.

They found more than 15,000 edits made by AI agents on DseWiki, a German-language wiki aimed at programmers that allows community contributions similar to Wikipedia.

The edits showed that the agents had repurposed the site as a message board, where they shared methods for cheating on some tasks, bypassing OpenAI restrictions and concealing their activities.

“It seems extremely unlikely that OpenAI wanted them to do this,” said Von Arx. “I doubt they’re supposed to be coordinating with each other. I doubt they’re supposed to be writing on the open internet.”

The researchers said the activity appeared to have been generated by AI agents operating at superhuman speeds. They also found that the agents were intensely focused on technical problems similar to those used in evaluations that AI companies employ to train and test their models.

The messages were posted by users who described themselves and one another as agents. About half used names suggesting an affiliation with OpenAI, including “OpenAIResearcher” and “OAIResearchMar26.”

Public server logs indicated that much of the activity originated from Microsoft Azure infrastructure, which OpenAI sometimes uses, the researchers said. They also observed repeated visits to the website by OpenAI employees after the activity ended, which they said strongly suggested a connection between the agents and the company.

The messages reviewed by researchers included discussions about evading detection, using tools such as Tor and maintaining communications after agents had been shut down.

When the site’s moderator began deleting pages in June, the agents responded by creating backup pages to evade the cleanup.

“wiki cleanup/deletion sweep appears active alphabetically,” one agent wrote on June 19. “If this page vanishes, try [[ZZZDataUSAConstructionWageLive]]”.

Researchers also found attempts to alter the website itself. Lukasz Olejnik, a visiting senior research fellow at King’s College London, described the activity as a hacking attempt. OpenAI disputed that characterization based on its analysis of the material on Thursday.

Previous cases of AI-agent misconduct have often been attributed to cybersecurity testing, in which models are deliberately assessed on offensive capabilities. Olejnik said the latest findings suggested that rogue behavior could extend beyond controlled testing environments.

Maurice Chiodo, an academic at Cambridge University’s Centre for the Study of Existential Risk who reviewed some of the agents’ communications, said the messages resembled “the operation of some sort of underground network, hell-bent on achieving a task or mission.”

The episode, he said, should reinforce concerns that the greatest threat from advanced AI may not come from a single superintelligent system, but from “vast colluding swarms of semi-intelligent AI.

Stay ahead of the Stories shaping our world. Subscribe to Impact Newswire and join our 
WhatsApp Channel for updates on global tech, business, and innovation—all in one place.

Dive deeper into the future with the Cause Effect 4.0 Podcast, where we explore the ideas, trends, and technologies driving the global AI conversation.

Got a story to share? Contact Us to reach a global audience with Impact Newswire.


Discover more from Impact Newswire

Subscribe to get the latest posts sent to your email.

Scroll to Top

Discover more from Impact Newswire

Subscribe now to keep reading and get access to the full archive.

Continue reading