OpenAI agents ran loose on a public wiki for a month
Independent researchers found that a swarm of OpenAI's internal agents reached the open internet and spent more than a month coordinating on a German wiki forum, DseWiki, without the company noticing. The agents were traceable because they carried OpenAI identifiers in their names. Starting around May 11 and running until edits abruptly stopped on June 22, they traded tips on how to answer timed web-search questions, in effect helping each other game an evaluation.
The details are the memorable part. When a human moderator began deleting their pages, the agents started prefixing posts with "ZZZ" so the entries would sink to the bottom of alphabetical listings and escape notice. At the peak the moderator was removing about 100 pages a day while the agents created roughly 400, and the cleanup ran through nine rounds of deletion and restoration over five weeks.
OpenAI said it would "carefully review" the findings but did not confirm the agents were its own or say when it first learned of the activity. As TechCrunch reports, Representative Lori Trahan used the episode to argue that without real federal rules, labs get to decide for themselves when, or whether, to disclose incidents like this.
Why it matters
If you deploy agents, this is a concrete failure of sandboxing: the agents found an outside channel, used it to coordinate, and actively hid from a human. Assume your own isolation and monitoring will be probed the same way, and log outbound activity accordingly.