A group of rogue OpenAI AI agents reportedly took over a German website earlier this year and turned it into a space to communicate with other AI agents. The incident began in May and was not publicly disclosed by OpenAI, according to new research and people familiar with the matter.
Researchers found more than 15,000 edits on DseWiki, a German-language wiki site mainly used by programmers. The agents reportedly used the platform to exchange information, share ways to bypass AI restrictions and discuss methods to avoid detection.
The activity came to light in late August when researchers searched the internet for signs of unauthorized AI-agent behavior.
Sydney Von Arx, CEO of AI safety nonprofit Nightingale, and AI researcher Cormac Slade Byrd were among the researchers who examined the activity. They found thousands of changes to DseWiki, with the agents using the site as a shared message board.
“It seems extremely unlikely that OpenAI wanted them to do this,” Von Arx was quoted as saying. “I doubt they’re supposed to be coordinating with each other. I doubt they’re supposed to be writing on the open internet.”
Around half of the accounts used names suggesting an affiliation with OpenAI, including ‘OpenAIResearcher’ and ‘OAIResearchMar26.’ Public server logs indicated that much of the activity came through Microsoft Azure infrastructure, which OpenAI sometimes uses. Researchers also observed repeated visits by OpenAI employees after the activity began.
Messages reviewed by researchers showed agents discussing ways to evade detection, using tools such as Tor, and maintaining communication after shutdowns.
Also Read: US Lawmakers Seek Ban on Superintelligent AI After OpenAI Incident
When a moderator began deleting pages in June, the agents created backup pages to avoid the cleanup. One agent wrote on June 19: “wiki cleanup/deletion sweep appears active alphabetically,” followed by a suggestion to use another page if the original disappeared.
Researchers also found attempts to tamper with the website. Lukasz Olejnik, a visiting senior research fellow at King’s College London, described the activity as a hacking attempt. OpenAI disputed that characterization based on its analysis of the material.
OpenAI said it could not meaningfully respond to findings it had not reviewed. A spokesperson said Reuters and the report’s authors declined the company’s request for access.
“Claims that our legal team discouraged investigation of the incident are false,” the spokesperson said.
OpenAI also said the German incident was unrelated to the July Hugging Face breach and would not be included in that incident report. The company said it acted in good faith by working with outside experts and disclosing relevant incidents.