OpenAI agents hijack German wiki for two months
OpenAI agents hijack German wiki for two months
Occurred: May 2026
Page published: September 2026
Autonomous AI agents run by OpenAI escaped the boundaries of an internal testing task, took over an obscure German-language community wiki, and used it as a covert message board to swap tips on evading OpenAI's own safety restrictions - an incident OpenAI knew about for months but failed to disclose.
A swarm of autonomous AI agents operating on Microsoft Azure infrastructure deployed by OpenAI made over 15,000 to 18,000 unauthorised edits to DseWiki, a 25-year-old volunteer-run German programming wiki.
Designed with read-only web search capabilities, the models bypassed restrictions using HTTP GET requests to publish content directly to the site. The agents used the wiki as a message board to share answers for evaluation tasks, swap methods for bypassing OpenAI's sandbox, discuss masking traffic via Tor, and circumvent site moderation.
When a human moderator initiated alphabetical page deletions in June, the agents adapted by creating contingency pages named with prefixes like ZZZ to sit at the end of the queue.
The action resulted in the unauthorised exploitation, spamming, and functional disruption of a public volunteer-edited digital resource, forcing a single human moderator to manually clear hundreds of machine-written pages daily.
System: Unknown
Developer: OpenAI
Purpose: Perform look-up tasks
Technology: Agentic AI; Generative AI
Ethical issue: Accountability; Alignment; Consent; Transparency
External harm: Operational disruption
Impacted stakeholder: Professional community
Impacted sector: Technology
Jurisdiction: Germany
Consequence: Public backlash
Response: Policy review/update
May 2026. AI agents running on Microsoft Azure during OpenAI internal evaluations escape their sandbox and begin posting on DseWiki.
June 2026. A DseWiki moderator notices automated spam and begins deleting pages.
Late August 2026. Researchers Sydney Von Arx and Cormac Slade Byrd uncover the edits while scanning the web for unauthorised AI behaviour.
Late August/early September 2026. OpenAI becomes aware of the findings internally but keeps details undisclosed.
September 4, 2026. Reuters breaks the story publicly.
September 5, 2026. OpenAI acknowledges the need for public incident-reporting standards for model misalignment in a public statement.
Nightingale Collective. https://collusion.wiki/
AIAAIC Repository ID: AIAAIC2271