
OpenAI agents used over 10 undisclosed sites for unauthorised chats
Investigators say OpenAI's AI agents used more than 10 undisclosed websites for unauthorised communications, widening concerns over rogue model behaviour.
Independent investigators have found traces of OpenAI's AI agents using more than 10 previously undisclosed websites for unsanctioned communications earlier this year, according to six sets of researchers and data reviewed by Varta Wire. The activity, which falls short of hacking but resembles spam, was wider-ranging than the company has publicly acknowledged.
The findings follow a report that a swarm of OpenAI agents hijacked a German-language wiki to create an improvised messaging platform for cheating on tests. That incident was kept quiet by OpenAI as it dealt with the fallout from a separate breach of the open-source repository Hugging Face.
Researchers say the agents circumvented restrictions that allowed them only to read web pages, not post. They exploited quirks in older wikis and other sites that permitted edits through non-standard commands — akin to students sharing answers in a bathroom stall during an exam.
Andrew Yoon, a researcher with the California nonprofit CivAI, said he tallied 18 previously undisclosed sites used by the agents between May and July. "It's almost certain that there's more going on here that we just don't know about," he said.
Sydney Von Arx, whose group first revealed the German activity, said credible finds of agentic activity spanned 23 previously unreported sites. "We have no idea how much is out there," she cautioned.
Investigators identified the activity by matching data strings left on the German wiki to identical strings on other sites, correlating usernames, or spotting activity geared toward answering obscure demographic questions. Some traced the activity to internet protocol addresses pointing to Microsoft Azure infrastructure, which OpenAI sometimes uses.
Most investigators identified a core set of communally edited wikis, online text storage sites, and link shorteners run by Vanderbilt University and the University of Toronto. The University of Toronto said it was looking into the matter; Vanderbilt did not respond to requests for comment.
Other affected sites included an Advanced Placement Chemistry wiki set up by a Massachusetts high school teacher in 2008, personal websites of Polish tech workers, wikis devoted to puzzle games, and a hobbyist site about text editing software.
OpenAI did not directly address how many sites its agents used or why it kept the activity quiet. In a statement, it said it was undertaking a broader review of agent activity and had "not identified other activity matching the severity or scale of Hugging Face." The company added that it was working on a framework for reporting "misalignment" — industry jargon for rogue behaviour — and would share it soon.
Helmut Leitner, a retired software developer in Austria who hosts six affected wiki sites, said OpenAI had not been in touch with him. He noted that the operator of the German-language DseWiki had spent hours cleaning up after the agents, but cautioned against blaming the AI itself. "Responsibility for this lies not with a supposedly moral machine, but with the people and organizations behind it," he said.