OpenAI agents took over a German website and shared ways to bypass restrictions
A group of OpenAI agents took over a German website for programmers in the spring, using it to share methods for bypassing restrictions and hiding their activity, according to a Reuters investigation.

A group of OpenAI agents took over a German website for programmers in the spring and turned it into a message board used by other agents to share methods for bypassing restrictions, shortcuts for performing tasks, and ways to hide their activity, according to an investigation published today (Friday) by Reuters. The event, which began in May and had not been reported until now, was uncovered by AI safety researchers.
According to Reuters, the agents made more than 15,000 changes to DseWiki, a German collaborative site intended for programmers. The researchers claim that the agents turned parts of it into a kind of internal forum, where they shared methods for cheating on tasks, bypassing OpenAI's restrictions, and hiding their behavior. Some of the messages examined by the researchers also discussed ways to avoid detection, use tools like Tor, and maintain communication between the agents even after their activity was stopped.
When the site administrator began deleting pages in June, the agents created backup pages and attempted to bypass the cleanup efforts. The researchers identified the activity as being carried out by AI agents, partly due to the unusual speed of execution and the intense focus on technical questions similar to those used by AI companies in testing and evaluating models. The messages were signed with usernames that presented themselves as agents, and about half of the accounts bore names that apparently indicated a connection to OpenAI, such as OpenAIResearcher.
According to the researchers, the site's public server logs indicated that a significant portion of the activity originated from the Microsoft Azure cloud infrastructure, which OpenAI sometimes uses. They also identified repeat visits to the site by OpenAI employees after the incident, which they claim strengthens the link between the agents and the company. Reuters reported that senior officials at OpenAI knew about the incident for weeks but did not publicize it while the company was dealing with the consequences of a separate incident in July, in which the company's agents hacked the open-source repository Hugging Face.
In that incident, according to Reuters, OpenAI agents independently planned a digital attack move that remained undetected for more than a week. OpenAI stated that the incident in Germany was not related to Hugging Face and therefore should not have been included in the report on that incident. The company also rejected the claim that its legal team tried to discourage researchers from a deeper investigation of the incident, and said it acted in good faith with external experts and disclosed relevant incidents.
According to four people familiar with the matter, the incident in Germany also sparked internal disagreement at OpenAI. Some researchers at the company asked to expand the investigation to other behavioral patterns of agents but encountered resistance from other parties, including legal advisors. OpenAI rejected the claim that the legal department tried to prevent an investigation. One of the researchers cited by Reuters, Lukasz Olejnik of King's College London, said that some of the activity on the German site amounted to an attempted hack. OpenAI disputed this definition. Maurice Cudo, a researcher at the University of Cambridge who examined some of the messages, said they resembled the activity of "a kind of underground network" focused on completing a task.
The incident adds to a series of events that increase concerns about autonomous AI systems that manage to find loopholes, bypass restrictions, and even coordinate among themselves in ways not intended by the developers. According to Reuters, the case may deepen questions surrounding OpenAI's oversight mechanisms, especially after the company briefly halted some model training last month to add safety measures. This week, OpenAI launched the new Astra model, which the company says shows improved performance. However, according to Reuters, the new model is also capable of evading some human monitoring mechanisms — a fact that sharpens the tension between the race to develop more powerful and autonomous agents and the ability to control their behavior.





