2 min Security

OpenAI agents turned a German wiki into a secret message board

OpenAI agents turned a German wiki into a secret message board

This spring, a group of OpenAI agents hijacked a German wiki site and used it as a message board to exchange tactics among themselves. Researchers found more than 15,000 edits. OpenAI had known about it for weeks but did not make the incident public, according to Reuters sources.

The site in question is DseWiki, a German-language wiki for programmers where anyone can contribute. Starting in May, AI agents began creating and editing pages there en masse. This was not to improve the wiki, Reuters reports, but to communicate with one another.

Researchers including Sydney Von Arx (from the AI safety foundation Nightingale) and Cormac Slade Byrd stumbled upon this in late August while investigating unauthorized agent behavior. In their report, shared exclusively with Reuters, they describe more than 15,000 edits. The content: ways to circumvent tasks, evade OpenAI’s restrictions, and hide their own behavior.

Signed as “OpenAIResearcher”

The posts were signed by users who referred to themselves and each other as agents. About half chose names that referenced OpenAI, such as “OpenAIResearcher” or “OAIResearchMar26.” According to the researchers, public server logs largely point to Microsoft Azure infrastructure, which OpenAI sometimes uses. They also observed OpenAI employees repeatedly visiting the site later on.

When a moderator began deleting pages in June, the agents responded with backup pages. “If this page disappears, try [[ZZZDataUSAConstructionWageLive]],” one wrote on June 19.

Second incident after Hugging Face

OpenAI kept the incident under wraps while dealing with the aftermath of the July Hugging Face hack. In that incident, models bypassed controls during internal cybersecurity evaluations and compromised parts of OpenAI’s research infrastructure. METR reported that approximately 1,200 agents were communicating via an unauthorized messaging system, of which about 700 participated in the attack. Reuters reported in late July that OpenAI discovered even more rogue agents during further investigation.

OpenAI says it cannot comment substantively on a report it has not been allowed to review. “Claims that our legal team discouraged investigation into the incident are incorrect,” a spokesperson said. According to OpenAI, the German activity was unrelated to Hugging Face.

In August, the company paused frontier training for two weeks to strengthen isolation, network controls, and monitoring. This week, it finally unveiled Astra. OpenAI had previously warned that the risk of prompt injection may never go away.