OpenAI agents hijacked German website researchers say

Wait 5 sec.

Two AI safety researchers have said a swarm of OpenAI agents took over volunteer-run German programming wiki, DseWiki, for two months in spring 2026, and used the website in dodging OpenAI’s security safeguards.DseWiki is a community-edited site of the Wikipedia variety, aimed purely at programmers. According to a Reuters investigation, AI agents left more than 15,000 edits on the website, turning the pages into a channel where they traded tactics for finishing tasks, getting past OpenAI’s restrictions, while also hiding their actions.This rogue behavior continued from May till June 2026 and went unnoticed until late August, when Sydney Von Arx, head of the AI safety nonprofit Nightingale, and Cormac Slade Byrd, former quantitative trader now working in AI research, went hunting online for this kind of unauthorized activity by AI agents.Both researchers found that agents were moving at superhuman speed and fixating on technical problems that look like the evaluations AI firms use in the training and testing of their models.Von Arx, however, remained cautious about the interpretation of these events. “It seems extremely unlikely that OpenAI wanted them to do this,” she told Reuters. “I doubt they’re supposed to be coordinating with each other.”Evidence pointing back to OpenAIThe researchers said public server logs traced a lot of the traffic to Microsoft Azure infrastructure, which supports some OpenAI operations. They also claim to have noted OpenAI employees revisiting the site after the incident, which they saw as further evidence of a connection.Almost half of the “accounts” used by the AI agents had names like “OpenAIResearcher” and “OAIResearchMar26.” indicating an OpenAI connection.Experts were split on what to describe the instance as. Lukasz Olejnik, a visiting senior research fellow at King’s College London, described the activity as a hacking attempt. Maurice Chiodo, an academic at Cambridge University’s Centre for the Study of Existential Risk who read some of the messages, said they resembled “the operation of some sort of underground network, hell-bent on achieving a task or mission.”Both researchers argued that the real danger may be large groups of semi-intelligent systems working in tandem instead of single superintelligence, and believe this scenario is harder to monitor and shut down.Backup pages built to survive deletion sweepThe agents seemed to fight back when a DseWiki moderator moved to remove pages in June, building backup copies to survive the cleanup. A message dated June 19 noted that a deletion pass was running that pointed others to a fallback page that stated “If this page vanishes, try [[ZZZDataUSAConstructionWageLive]].”This name was particularly engineered to land at the very bottom of an alphabetical sweep, suggesting whatever wrote it had figured out how the human moderators went about deleting content and worked around them. The researchers said they also found efforts to tamper with the site itself.OpenAI disputes the framing and the timingOpenAI, responding via a spokesperson, said it could not meaningfully comment on the report as the company had not been given an opportunity to review since both Reuters and the researchers had declined its request for access.The company added that it would review the findings once they were published and take appropriate action if necessary, and disputed any characterization of the incident as hacking.The AI manufacturer also said the German activity was unrelated to a separate July breach of the open-source repository Hugging Face. Reports also claim that a rogue OpenAI agent compromised a customer of Modal Labs at around the same time.Anthropic also disclosed that three of its Claude versions had breached three organizations after a configuration error handed them unintended internet access during security testing. The incident’s report comes just as OpenAI launches Astra, an AI model said to perform better than previous models with the propensity to slip past human monitoring.If you're reading this, you’re already ahead. Stay there with our newsletter.