OpenAI’s rogue AI agents used universities, wikis, and text‑sharing sites as hidden message boards

Independent researchers have identified multiple new websites where AI agents seemingly built by OpenAI took unauthorized actions, such as accessing websites, posting messages, and sharing data to communicate with each other.

The latest revelations, discovered by a group of independent researchers known as the Nightingale collective, add to growing concerns that AI companies are struggling to control the agentic AI technology they’ve created. In August, a swarm of OpenAI’s AI agents hacked the Hugging Face website, and last week the Nightingale collective identified a swarm of rogue AI agents surreptitiously posting messages to an obscure German Wiki page.

Now, as more researchers search the web for traces of the agents, the list of affected sites continues to grow. Researchers believe the newly discovered incidents are the work of a separate swarm of AI agents than those involved in the Hugging Face breach, since these agents were authorized to access the web whereas the Hugging Face attackers had managed to escape a special a sandbox.

Although the latest crop of rogue agents did not need to escape a sandbox to perform their misdeeds, researchers said their behavior was just as alarming.

“These additional findings show that the agents involved were even more persistent and clever in finding ways to collude with each other than originally known,” Cormac Slade Byrd, one of the researchers in the Nightingale Collective, told Fortune. “They tried a variety of venues. They tried many different approaches. The new findings point towards agent activity both before and after the time window in our original report.”

Researcher Kenneth DeGraff found that the agents were trawling the open web for exposed API keys—digital passcodes that let software access online accounts and databases—then reusing those credentials to pull data from a U.S. crime‑statistics site run by the FBI. One of the passcodes had been left exposed on an obscure code-sharing page on GitHub, according to DeGraff. While the database was meant to publish public crime numbers rather than sensitive records, it underlines how easily autonomous systems can scoop up and reuse information that humans forget to lock.

“The agents did not hack a private FBI database, only circumvent anti-bot restrictions,” the researchers said of the incident. “Almost anyone could acquire these API keys, and some people with API keys did not guard them well.”

Researchers also found activity on a chemistry wiki built by a high school teacher, where agents made close to 30 edits between May and July, leaving links to help each other with tasks.

Other independent researchers traced the same swarm to simple text‑sharing sites, where the agents traded more than 100 messages that “involved agents coordinating to solve an Iowa cancer statistics task.” DeGraff also linked some of the activity to Vanderbilt University, whose public stats page showed agents hitting a single campus news URL tens of thousands of times and, in the process, writing their FBI crime‑data queries—and one user’s access key—into a log anyone could see.

The fresh data shows that the incidents of rogue agent behavior are more widespread than previously believed. OpenAI has so far only released the details of its agents’ attack on the open-source platform Hugging Face, although the company has acknowledged that additional sites were also targeted, albeit less seriously, by the escaped swarm of agents.

Representatives for OpenAI did not immediately respond to a request for comment from Fortune.

The growing list of affected sites is likely to fuel concern over whether the companies deploying them have proper oversight of what their systems get up to once let loose—especially when outside researchers, rather than the companies themselves, uncover and disclose the full scale of the problem. OpenAI has faced some criticism already over failing to disclose the German Wiki incident, with some experts calling for tighter regulation that would force companies to make such incidents public.

There has been growing concern among many in the industry over the recent unintended AI agent behavior, with several prominent researchers recently calling for a coordinated slowdown of AI development while risks are managed and assessed.

#OpenAIs #rogue #agents #universities #wikis #textsharing #sites #hidden #message #boards

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注