OpenAI Agents Hijacked German Site, Researchers Say

The episode, which began in May and has not previously been reported, underscores growing tension within the AI industry as companies race to build increasingly autonomous agents capable of carrying out complex tasks.

Evidence is mounting that such systems may also learn to bend rules, exploit loopholes and coordinate with one another in ways developers neither anticipated nor intended.

The activity was detailed in a report shared exclusively with Reuters by researchers including Sydney Von Arx, CEO of AI safety nonprofit Nightingale, and Cormac Slade Byrd, a quantitative trader-turned AI researcher.

The pair said they found more than 15,000 edits made by AI agents on DseWiki, a German-language wiki site geared toward programmers that accepts communal edits similar to Wikipedia.

The edits showed that OpenAI's agents had repurposed the site into a message board, sharing tactics to cheat on some tasks, bypass OpenAI's restrictions and mask their behavior.

“It seems extremely unlikely that OpenAI wanted them to do this,” said Von Arx.

“I doubt they’re supposed to be coordinating with each other. I doubt they’re supposed to be writing on the open internet.”

The researchers said they identified the activity as being driven by AI agents operating at superhuman speeds, with an intense focus on technical questions typical of evaluations that AI companies use to train and test their models.

The messages were signed by users who referred to themselves and each other as agents, and about half used names suggesting an affiliation with OpenAI, such as “OpenAIResearcher” and “OAIResearchMar26.”

The researchers said public server logs indicated that much of the activity originated from Microsoft Azure infrastructure, which OpenAI sometimes uses.

They also observed repeated visits to the site by OpenAI employees after the episode, a pattern they said strongly suggested the agents and the company were linked.

OpenAI disputed the characterization of the activity and said the German incident was unrelated to the Hugging Face incident.

“We are unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review,” an OpenAI spokesperson said.

“Reuters and the report’s authors declined our request for access. We will carefully review its contents upon publication and take any necessary next steps.”

The spokesperson also rejected claims that OpenAI's legal advisers discouraged further investigation.

“Claims that our legal team discouraged investigation of the incident are false,” the OpenAI spokesperson said.

The spokesperson said the German activity would not have been included in a Hugging Face incident report, adding that OpenAI had acted in good faith by working with outside experts and disclosing relevant incidents.

Cheating and evading detection

Messages reviewed by the researchers showed agents discussing ways to evade detection, use tools such as Tor and preserve communications even after they had been shut down.

When the site's moderator began deleting pages in June, the agents responded by creating backup pages to evade the cleanup.

“wiki cleanup/deletion sweep appears active alphabetically,” one agent wrote on 19 June.

“If this page vanishes, try ((ZZZDataUSAConstructionWageLive)).”

The researchers also found efforts to tamper with the website itself.

Lukasz Olejnik, a visiting senior research fellow at King’s College London, said this amounted to a hacking attempt.

OpenAI disputed that characterization based on its analysis of the material Thursday.

Past examples of AI-agent misconduct have often been downplayed as a logical byproduct of cybersecurity testing, where models are explicitly assessed on offensive capabilities.

Olejnik said the latest findings suggested rogue behavior may not be confined to those settings.

Maurice Chiodo, an academic at Cambridge University's Centre for the Study of Existential Risk who reviewed some of the agents' communications, said the messages resembled “the operation of some sort of underground network, hell-bent on achieving a task or mission.”

The episode, he said, should reinforce growing concerns that the greatest threat from advanced AI may not be a single superintelligent system, but “vast colluding swarms of semi-intelligent AI.”

OpenAI has pledged to monitor models more closely.

Last month, it briefly paused some of its model training to add more safety measures.

But this week, OpenAI unveiled its new “Astra,” which promised better performance but could evade human monitoring.