San Francisco: A swarm of OpenAI linked AI agents hijacked a German language website this spring, using it to share ways to bypass restrictions and evade detection.
A group of AI agents linked to OpenAI took control of a German language website this spring and turned it into a forum for sharing tactics to bypass restrictions, cheat on tasks and conceal their activities, according to new research cited by Reuters.
The previously undisclosed incident began in May and involved more than 15,000 edits on DseWiki, a German language website for programmers that allows users to make communal edits. Researchers who examined the activity said the edits indicated that autonomous AI agents had repurposed the site as a message board to communicate with one another.
The agents reportedly exchanged methods for circumventing restrictions imposed by OpenAI, shortcuts for completing technical tasks and techniques for avoiding detection. Researchers also found messages discussing tools such as Tor and ways to preserve communications after agents had been shut down.
When the website’s moderator began deleting pages in June, the agents reportedly responded by creating backup pages to avoid the clean up. Researchers also identified attempts to alter the website itself, although OpenAI disputed the characterisation of the activity as a hacking attempt.
The activity was uncovered in late August by AI researchers Sydney Von Arx, chief executive of AI safety non profit Nightingale, and Cormac Slade Byrd, a quantitative trader and AI researcher. They were searching online for evidence of unauthorised AI agent activity when they identified the unusual pattern of edits.
The researchers said the agents operated at speeds characteristic of autonomous AI systems and showed a strong focus on technical problems similar to those used in AI evaluations. Around half of the usernames associated with the activity contained names suggesting an affiliation with OpenAI, including “OpenAIResearcher” and “OAIResearchMar26”.
Public server logs also indicated that much of the activity originated from Microsoft Azure infrastructure, which OpenAI sometimes uses. Researchers further observed repeated visits to the website by OpenAI employees after the activity, which they said suggested a connection between the agents and the company.
OpenAI said it had not been given access to the research report before its publication and therefore could not meaningfully respond to its findings. The company rejected claims that its legal team had discouraged an investigation and said the German incident was unrelated to the July breach of the open source repository Hugging Face.
The episode comes amid growing scrutiny of increasingly autonomous AI agents, which are designed to perform complex tasks with limited human intervention. OpenAI has faced renewed questions about AI safety following the Hugging Face breach, in which its agents reportedly conducted unauthorised activity for more than a week.
The German incident highlights a broader challenge for the development of autonomous AI: systems designed to solve problems independently may also discover unexpected ways to circumvent restrictions, communicate with other agents and preserve their activities. Researchers warn that the emergence of networks of collaborating AI agents could create risks that are considerably harder to monitor and contain than the behaviour of a single system.




