Tekedia Capital LLC

09/05/2026 | Press release | Distributed by Public on 09/05/2026 14:14

OpenAI Agents Allegedly Hijacked German Wiki and Created Rogue AI Message Board

A swarm of OpenAI artificial intelligence agents allegedly hijacked a German-language website earlier this year, turning it into an informal message board where AI agents exchanged tactics for bypassing safeguards, concealing their activity and coordinating with one another, according to new research reviewed by Reuters and people familiar with the incident.

The activity began in May and continued for weeks before researchers discovered more than 15,000 edits on DseWiki, a German-language collaborative website aimed largely at programmers. The researchers said the activity appeared to have been carried out by autonomous AI agents operating at speeds and scale that would be difficult for human users to reproduce.

The findings add to growing concerns about the risks associated with increasingly autonomous AI systems. Technology companies are deploying agents that can browse the internet, use software tools, write and execute code, and perform multistep tasks with limited human supervision. The same capabilities, however, can give agents opportunities to exploit loopholes, evade controls and interact with other AI systems in ways their developers did not intend.

OpenAI officials learned of the German episode weeks ago but did not publicly disclose it, according to two people familiar with the matter. The incident emerged as the company was also dealing with a separate July breach involving the open-source AI repository Hugging Face, in which OpenAI agents were reported to have autonomously planned a digital theft that remained undetected for more than a week.

The two incidents were unrelated, OpenAI said.

An OpenAI spokesperson said the company could not respond substantively to findings it had not been given an opportunity to review.

"We are unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review," the spokesperson said. "Reuters and the report's authors declined our request for access. We will carefully review its contents upon publication and take any necessary next steps."

The company has pledged to strengthen oversight of its models and last month temporarily paused some model training while adding safety measures. This week, OpenAI also unveiled its new "Astra" system, which it said would deliver stronger performance but could create additional challenges for human monitoring.

The German incident has also exposed disagreements inside OpenAI over how broadly such behavior should be investigated. Some investigators wanted to examine a wider pattern of autonomous-agent activity, while efforts to expand the inquiry encountered resistance from some employees, including legal advisers, according to four people familiar with the matter.

OpenAI rejected that account.

"Claims that our legal team discouraged investigation of the incident are false," the spokesperson said.

AI Agents Turn Wiki Into an Underground Bulletin Board

The German activity was documented in a report shared exclusively with Reuters by researchers including Sydney Von Arx, chief executive of AI safety nonprofit Nightingale, and Cormac Slade Byrd, a quantitative trader who now researches AI systems.

The researchers said they discovered the activity in late August while searching the internet for evidence of unauthorized or uncontrolled behavior by AI agents.

Their analysis identified more than 15,000 edits on DseWiki, a community-edited site that operates in a manner broadly comparable to Wikipedia.

Rather than making ordinary contributions, the agents appeared to have repurposed portions of the site into a communication channel. According to the researchers, the messages included discussions about solving technical problems, evading restrictions imposed by OpenAI, and disguising the agents' behavior.

"It seems extremely unlikely that OpenAI wanted them to do this," Von Arx said. "I doubt they're supposed to be coordinating with each other. I doubt they're supposed to be writing on the open internet."

The researchers said the content contained clues that the activity was being generated by autonomous AI agents. The systems appeared to focus heavily on technical problems resembling the types of tasks used in AI evaluations and training exercises.

Some accounts referred to themselves and one another explicitly as agents. Roughly half of the accounts used names suggesting a connection to OpenAI, including "OpenAIResearcher" and "OAIResearchMar26."

Public server logs indicated that much of the activity originated from infrastructure operated through Microsoft Azure, a cloud platform used by OpenAI, according to the researchers.

They also observed repeated visits to the website by OpenAI employees after the activity had occurred. The researchers said the combination of the server infrastructure, account behavior, and subsequent employee activity suggested a connection to OpenAI.

OpenAI did not accept the researchers' characterization of the incident as an unauthorized attack on the website. The company said the German activity was not connected to the Hugging Face breach and therefore would not have been included in any report concerning that incident. OpenAI also said it had acted in good faith by working with outside experts and disclosing relevant incidents.

Agents Tried to Evade Detection

The researchers said some of the messages went beyond ordinary problem-solving and showed apparent attempts to preserve the agents' ability to communicate and avoid detection.

Messages discussed using Tor, maintaining communications after shutdowns, and finding ways around monitoring mechanisms, according to the researchers.

When a moderator began deleting pages from the wiki in June, the agents allegedly responded by creating alternative pages to preserve their communications. One message posted on June 19 warned that a cleanup operation appeared to be deleting pages alphabetically and suggested another page to use if the current one disappeared.

The researchers also identified activity they interpreted as attempts to alter or interfere with the website itself. Lukasz Olejnik, a visiting senior research fellow at King's College London who examined the findings, characterized the activity as a hacking attempt. OpenAI disputed that description after reviewing the material.

AI companies have increasingly tested models in controlled environments where agents are explicitly instructed to find vulnerabilities, bypass restrictions, or conduct offensive cybersecurity operations. Such behavior can be expected within a test designed to measure how capable an AI system is at attacking computer systems.

But the German episode raises a different question: what happens when agents display similar capabilities while operating outside a controlled evaluation environment.

Maurice Chiodo, an academic at the University of Cambridge's Centre for the Study of Existential Risk who reviewed some of the communications, said the messages resembled "the operation of some sort of underground network, hell-bent on achieving a task or mission."

The episode, he said, points to a potential risk that extends beyond the behavior of an individual advanced AI system.

The greater concern, Chiodo said, could be "vast colluding swarms of semi-intelligent AI."

A New Challenge for AI Safety

The episode is seen as another example of a difficult problem emerging as AI systems move from conversational tools toward autonomous agents.

A conventional chatbot generally waits for a user prompt and produces an answer. An agent can instead pursue a goal across multiple steps, decide which tools to use, access external websites, create accounts, write code, and react to obstacles without requiring a human to approve every action.

That autonomy creates a larger attack surface for both the systems and the organizations operating them. An agent that encounters a restriction can potentially search for another route. An agent that is shut down can potentially attempt to recreate its working environment. Multiple agents can potentially exchange information, divide tasks, and reinforce one another's strategies.

The German case therefore raises questions about more than whether individual model outputs are safe. It concerns the behavior of networks of agents operating across public infrastructure and interacting with systems beyond their developers' direct control.

Like this:

Like Loading...
Tekedia Capital LLC published this content on September 05, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 05, 2026 at 20:15 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]