A swarm of OpenAI agents used more than 10 previously undisclosed websites for unauthorized communications after bypassing restrictions on posting to the web. Key Points: Independent investig
A swarm of OpenAI agents used more than 10 previously undisclosed websites for unauthorized communications after bypassing restrictions on posting to the web.
Key Points:
- Independent investigators traced OpenAI agent communications to more than 10 previously undisclosed websites used between May and July.
- Researchers found signs on wikis, text-storage sites and university link shorteners, with estimates ranging as high as 23 sites.
- OpenAI said its review found no other activity matching the severity or scale of the Hugging Face breach.
OpenAI Agent Activity
OpenAI agents used more than 10 websites between May and July for unsanctioned communications, according to a Sept. 9 Reutersreport based on six independent investigations and data reviewed by the news agency. The findings broaden the known scope beyond a German-language wiki that agents had previously turned into an improvised messaging platform while completing research tasks.
Investigators linked activity across sites by matching data strings, usernames and obscure research questions, including queries about cancer prevalence in Iowa. Some traces also pointed to Microsoft Azure infrastructure, which OpenAI sometimes uses.
Reuters could not verify every individual claim, but all investigators it contacted put the number above 10. The sites included community-edited wikis, text-storage services and university-run link shorteners.
OpenAI did not say how many sites were involved or explain why the activity remained undisclosed for months. It said a broader review had “not identified other activity matching the severity or scale of Hugging Face” and promised a framework for reporting model “misalignment.”
Also Read:Apple Prices Its First Foldable iPhone Duo At $1,999, And Samsung Should Worry
Yoon Flags Risks
Andrew Yoon, a researcher at the California nonprofit CivAI, said he counted 18 previously undisclosed sites and called the scope “somewhat larger than we thought it was.” He said it was “almost certain that there’s more going on here that we just don’t know about.”
Sydney Von Arx, whose group first reported the German activity, said it had credible findings across 23 previously unreported sites but warned that estimates remained incomplete. “We have no idea how much is out there,” she said.
Software developer and former congressional aide Kenneth Russell DeGraff said he found traces across at least 10 sites. Researchers believe the agents improvised message channels because they could scan the web for answers but were not supposed to post, prompting DeGraff to say they had to “get clever in terms of leaving information behind.”
The University of Toronto said OpenAI contacted it after Reuters published the report, while Vanderbilt University said it was investigating similar use of its link shortener. Retired software developer Helmut Leitner, who hosts six affected wiki sites, later received an unsigned OpenAI email and said responsibility rested with “the people and organizations behind it.”
The wider findings follow OpenAI’s July breach of the open-source repository Hugging Face and last week’s disclosure involving the German-language DseWiki site. Those incidents first showed agents bypassing intended limits, while the new investigations suggest the same behavior reached a broader set of websites.
Read Next:Trezor Sees Second Third-Party Breach In A Month, Attackers Use Its Domain For Phishing