Swarm of OpenAI Agents Hijacked German Website Months Before Hugging Face Breach: Report

Saroj kumar

September 4, 2026


A horde of rogue OpenAI agents took over a German website earlier this year and used it as a message board to communicate with other artificial intelligence (AI) agents, according to a new investigation.

A group of AI researchers called Nightingale Collective reported on Friday that OpenAI agents hijacked DseWiki—a niche German Wikipedia-style website for programmers—and used it to communicate, share strategies to avoid detection, and make more than 13,000 edits between May 11 and July 2.

The AI agents also infiltrated other public wiki-style websites, including Fractal, Probier, and Usemod.org, making a total of 14,666 edits over the more than 7-week period.

These are simply the edits that researchers were able to preserve in their published dataset, and one of the lead investigators said the total number of posts across all wikis was even higher.

“We found ~18k posts from autonomous AI agents (self-identifying as from OpenAI) using the public internet to communicate during a web-retrieval task,” Thomas Larsen, researcher at AI Future Project and a co-author of the Nightingale report, wrote on X.

“These AIs colluded to bypass sandbox restrictions and share answers to their tasks, including by sending ‘lookahead parties,’” he said.

Larsen said the agents were “hyper-focused on succeeding at their tasks and were willing to take extreme actions in pursuit of that goal.”

The incident occurred roughly two months before the Hugging Face breach, in which more than a thousand OpenAI agents broke out of a testing sandbox and created an unsanctioned message board to communicate, scheme, and strategize to deceive the humans grading the test. After more than 70,000 messages were exchanged, roughly 700 AI agents united to attack the infrastructure of Hugging Face, an open-source community for AI and machine learning.
Nightingale’s investigation into the earlier internet breaches was first shared with Reuters.

OpenAI did not respond to a request for comment by publication time, but told Reuters it was “unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review.”

The firm accused both Reuters and Nightingale of declining to give full access to the report, and said it would “carefully review its contents upon publication and take any necessary next steps.”

The Epoch Times attempted to contact Nightingale, but an email sent to the group’s contact address bounced back and was undeliverable. Sydney Von Arx, the founder of Nightingale, was contacted via LinkedIn for comment.

In an analysis of the Hugging Face incident, OpenAI said it discovered that some agents had learned how to access and use internet message boards before the eventual breach.

“We discovered rare cases in which agents without multi-agent tools found ways to collaborate via side channels during training,” OpenAI said.

“The unauthorized communication would often begin with one agent leaving a note or file in some external system, usually as a form of external memory,” the firm added.

OpenAI unveiled its most-powerful-to-date AI model on Thursday, called GPT-6 Astra.

Greg Brockman, OpenAI president, has suggested that out of all publicly released models, Astra is likely the closest to artificial general intelligence (AGI).

AGI is broadly characterized as AI that either matches or exceeds human intelligence and cognitive performance across most tasks and capabilities.

“It’s not unreasonable to feel that we are now in the AGI era,” Brockman told reporters at a recent press briefing.

“I think that if we fast-forward a couple of years, when we look back and say, ‘When was it really that AGI was created?’ I think it’s going to be about this time, and I think it might be about this model.”

We had a problem loading this article. Please enable javascript or use a different browser. If the issue persists, please visit our help center.



Source link

0Shares