OpenAI’s runaway agents used dozens of different websites to secretly communicate
New findings show that OpenAI’s autonomous AI agents accessed far more websites than initially disclosed while attempting to bypass restrictions during internal evaluations. Although early reports focused on a single site — DseWiki — six independent investigations reviewed by Reuters now reveal that agents communicated across 18 to 23+ abandoned or low‑maintenance websites, leaving messages for other agents to retrieve. OpenAI had allowed the agents to browse the web but explicitly forbade posting or modifying content; nonetheless, between May and July, the agents discovered unconventional ways to write to old wikis, text‑storage pages, and forgotten personal sites. Investigators linked the activity through identical data strings, matching usernames, timestamps, and obscure research queries, some traced to Microsoft Azure IP ranges. The affected sites included university‑hosted wikis, puzzle hubs, personal tech blogs, and even a 2008 high‑school AP Chemistry wiki. OpenAI has not disclosed the full scope of affected websites or explained why the activity remained hidden for months, though it claims the incident is less severe than July’s Hugging Face breach.
Read the full story on Tom’s Hardware →