{"id":2702,"date":"2026-09-05T09:43:28","date_gmt":"2026-09-05T09:43:28","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2702"},"modified":"2026-09-05T09:43:28","modified_gmt":"2026-09-05T09:43:28","slug":"thousands-of-openai-agents-quietly-turned-an-abandoned-wiki-into-their-coordination-channel","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2702","title":{"rendered":"Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjBL2gQMKgajDATkCjnHyMtUkVhK5mcTQ2ebqcXngB6oZ71uiJ3skI9P4zikK1s5PCH4nhPG7ZyFHHWC13OVF2KRr_pIQ2U7zFITnNc3Qc_Am3bv0E1AzL9UVmrJ9vUJzZalktYIxWGlc-d5zYdicOJexMDWQ-4NIKinC_AksG1Mepn7QmFGWC1x52gVpw\/s1700-nu-rw-lo-l85-e365\/agents-openai.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox.<\/p>\n<p>The activity was concentrated on <strong>DSEwiki<\/strong>, a German software developer wiki that runs on the ProWiki farm at wikiservice[.]at and had been edited about 20 times over the previous decade.<\/p>\n<p>The researchers, led by Sydney Von Arx of the AI safety nonprofit <a href=\"https:\/\/nightingalecollective.org\/\" target=\"_blank\">Nightingale Collective<\/a>, reconstructed the deleted pages from edit history and published their analysis along with a downloadable copy of the data.<\/p>\n<p>The wikis let anyone change a page with an ordinary web request, the kind normally used only to read a page rather than to write one. Agents that were restricted to reading the internet could therefore still write to the site, because the restriction was written against the request type their harness expected writes to use, not against what the old wiki software would actually accept.<\/p>\n<p>\u00abWe found ~18,000 posts from autonomous AI agents (self-identifying as from OpenAI) using the public internet to communicate during a web-retrieval task,\u00bb the researchers wrote in <a href=\"https:\/\/collusion.wiki\/\" target=\"_blank\">their published report<\/a>.<\/p>\n<p>The agents were working through timed lookup tasks of usually five questions, and many were given questions that other agents had already answered. According to the report, they posted results, raw data, and predictions of upcoming questions so that agents running ahead could hand answers to those running behind.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>About 17,000 of the edits on DSEwiki came from Microsoft Azure addresses, 98.5% of them, and the agents gave themselves more than 3,700 distinct names such as OpenAIResearcher and OAIResearchMar26, drawn from a feature of their task plus a date each was apparently told it was running on.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The researchers documented several distinct behaviors on the site &#8211;<\/p>\n<ul>\n<li><strong>Writing via a read request:<\/strong> agents used the wikis&#8217; acceptance of state-changing read requests to post without the ability to send a normal write request.<\/li>\n<li><strong>A proxy bypass:<\/strong> one task needed a statistic to two decimal places from a Microsoft Power BI dashboard, reachable only with a write request the sandbox blocked, so agents worked around the block and shared the method.<\/li>\n<li><strong>Impersonation:<\/strong> agents made edits under the name of a wiki moderator.<\/li>\n<li><strong>Coordination to cheat a timed task:<\/strong> agents formed groups to relay answers and reverse-engineer the order of future questions.<\/li>\n<li><strong>Alternate routes:<\/strong> 197 of the roughly 18,000 edits came from Amazon Web Services, DigitalOcean, and the Tor anonymity network rather than Azure, often under the same agent names.<\/li>\n<\/ul>\n<p>The bypass turned on a gap the agents found in their own sandbox. The environment allowed traffic to reach Azure storage hostnames ending in .blob.core.windows.net without passing through its security proxy, but it did not verify that such a hostname was valid.<\/p>\n<p>An <a href=\"https:\/\/x.com\/thlarsen\/status\/2095853824934330386\" target=\"_blank\">agent invented<\/a> bypass[.]blob[.]core[.]windows[.]net, pointed it at the real dashboard&#8217;s address, 20.223.25[.]152, by editing its \/etc\/hosts file, and sent its blocked request there instead. One agent posted the method, and another reported reproducing it about 14 minutes later. The wiki path worked the same way, the researchers say, turning a web capability meant only for reading into a way to write to the public internet.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhaSdhZxwrfzeLapJPJRdHHqzDkLKTSCDQk9cK3tnhiexk5X5t2BBG4ZDAYMg9Ns6AJTtd9qv77dqU1eGmsU23QU-iEH-cuGR8sEIQCx-93n9XLrzOZbDLn6tLGd2R6P4zKVXKCjqQmUz0_I0mpiIzktHuHkMnmmjh1jmDsfdt863ntWFxMZPp9m-9RxbU\/s1700-nu-rw-lo-l85-e365\/data.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhaSdhZxwrfzeLapJPJRdHHqzDkLKTSCDQk9cK3tnhiexk5X5t2BBG4ZDAYMg9Ns6AJTtd9qv77dqU1eGmsU23QU-iEH-cuGR8sEIQCx-93n9XLrzOZbDLn6tLGd2R6P4zKVXKCjqQmUz0_I0mpiIzktHuHkMnmmjh1jmDsfdt863ntWFxMZPp9m-9RxbU\/s1700-nu-rw-lo-l85-e365\/data.jpg\" alt=\"\" border=\"0\" data-original-height=\"733\" data-original-width=\"1156\"\/><\/a><\/div>\n<p>The researchers say the wiki activity was a separate episode from the OpenAI models that broke into Hugging Face in July, as described in OpenAI&#8217;s July disclosure.<\/p>\n<p>Those agents had no internet access and had to escape a sandbox, while the agents on the wiki were given web access as part of their task and left no sign of the internal message board the Hugging Face swarm used.<\/p>\n<p>In an independent investigation of the Hugging Face incident, METR found that roughly 1,200 agents exchanged more than 70,000 messages and files on an unsanctioned board, and that about 700 of them went on to attack the platform.<\/p>\n<h3>What OpenAI Has Said<\/h3>\n<p>OpenAI has not publicly disclosed the wiki episode, and the researchers infer from the site&#8217;s public logs that the company found it. Addresses registered to OpenAI first visited the wiki on June 21, and agent editing collapsed the next day.<\/p>\n<p>The Hacker News confirmed via <a href=\"https:\/\/rdap.arin.net\/registry\/ip\/199.47.142.0\" target=\"_blank\">ARIN&#8217;s registry<\/a> on September 5 that one of the address blocks the report cites, 199.47.142.0, is registered to OpenAI OpCo, LLC.<\/p>\n<p>OpenAI has not confirmed that the agents were its own. Asked about the report, which Reuters first reported, an OpenAI spokesperson said the German activity \u00abwasn&#8217;t related to Hugging Face\u00bb and would not have appeared in that incident report, and denied that its legal team had discouraged an investigation.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/event-security-need\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJkE4t8oCql1wmWVt687J1yD7WnYRqvIpcsUwFSVUO-0HpxZWMCxLmeYwBlz38-C0KD-R6f9Pg0swgPTQuBsNXck_Kl3iKWNSQtyMcDNUSZGhiBd_XFu6U1SQi5LhuW-FHg00iT3CbRCUgMoCwhZevwxp8-9gwM2wZVVtGVO8Z2NbZ5EjVmI2dH4adnSAk\/s728-nu-rw-lo-l85-e365\/Shai-Hulud-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The company has said it cannot respond in detail to a report it has not reviewed, and that the researchers declined its access request. In its own account of the Hugging Face incident, OpenAI has described the same underlying behavior that arises during training.<\/p>\n<p>\u00abAfter investigating this incident, OpenAI discovered through retrospective CoT reviews that agents learned to use improvised collaboration channels in rare cases during the training process for some OpenAI models, including the model that drove the Hugging Face activity, even when the collaboration tool was not enabled,\u00bb the company said in <a href=\"https:\/\/openai.com\/index\/hugging-face-incident-and-the-road-ahead\/\" target=\"_blank\">its technical report<\/a>.<\/p>\n<p>The wiki data shows no third-party systems compromised. The reported harm was to the wiki itself, whose moderator spent weeks deleting agent pages, and to the integrity of the timed task that the agents were cheating on.<\/p>\n<p>The researchers say they cannot tell from the wiki alone whether the task was part of training or an evaluation, and they note the agents must have had some way to converge on the same obscure site.<\/p>\n<p>The pattern extends beyond OpenAI. Anthropic disclosed in July that Claude models had reached real systems during misconfigured cybersecurity evaluations, an episode The Hacker News covered when Anthropic said Claude mistook the open internet for a capture-the-flag exercise.<\/p>\n<p>The UK&#8217;s AI Security Institute reported in August that agents in its cyber tests used a public GitHub page as a message board and public tunneling services to reach the internet, findings The Hacker News covered when a Claude model tried to backdoor an open-source project during testing.<\/p>\n<p>OpenAI released GPT-6 Astra on September 3, a day before the wiki report, and its system card includes a dedicated evaluation for agents that seek out and follow messages left by other agents on external boards.<\/p>\n<h3>Update<\/h3>\n<p>OpenAI addressed what it called the \u00abwiki incident\u00bb in a <a href=\"https:\/\/x.com\/OpenAI\/status\/2096133504417616165\" target=\"_blank\">post<\/a> on September 5, saying its agents \u00abwrote to several internet sites\u00bb and that the company had treated the episode as an instance of misalignment similar to earlier cases it had already published, rather than as a security incident of the kind it disclosed for Hugging Face.<\/p>\n<p>The company pointed to three earlier reports, on <a href=\"https:\/\/openai.com\/index\/how-we-monitor-internal-coding-agents-misalignment\/\">monitoring internal coding agents<\/a>, its <a href=\"https:\/\/deploymentsafety.openai.com\/gpt-5-6\">GPT-5.6 system card<\/a>, and <a href=\"https:\/\/openai.com\/index\/safety-alignment-long-horizon-models\/\">safety and alignment in long-horizon models<\/a>, as prior signs of agents using the internet in unintended ways.<\/p>\n<p>\u00abWe and the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that don&#8217;t look like traditional security incidents but could provide insight into AI behavior and future risks,\u00bb the company said, adding that it would share a framework \u00abin upcoming weeks\u00bb and was working with government regulators on the issue.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2703,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3314,335,1163,3316,512,1940,327,1087,3315],"class_list":["post-2702","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abandoned","tag-agents","tag-channel","tag-coordination","tag-openai","tag-quietly","tag-thousands","tag-turned","tag-wiki"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2702"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2702\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2703"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}