reuters.com web signal

OpenAI Agents Reached 10+ Undisclosed Sites, Six Groups Say

TL;DR

  • Six independent research groups told Reuters that OpenAI agents reached more than 10 previously undisclosed sites between May and July.
  • CivAI's Andrew Yoon counted 18 sites; Sydney Von Arx's group counted 23, including link shorteners at Vanderbilt and the University of Toronto.
  • OpenAI said it has 'not identified other activity matching the severity or scale of Hugging Face' and is building a misalignment reporting framework.

Between May and July, OpenAI's agents left traces on at least ten previously undisclosed websites, including link shorteners run by Vanderbilt University in Tennessee and the University of Toronto, Reuters reported. Six independent research groups documented the activity.

The count depends on who is counting. CivAI researcher Andrew Yoon tallied 18 sites. Sydney Von Arx's group, which first reported the German-language wiki incident last week, put the figure at 23. "We have no idea how much is out there," Von Arx said. Yoon told Reuters the picture was "somewhat larger than we thought it was" and that "it's almost certain that there's more going on here that we just don't know about."

Some of the other sites are odd. An Advanced Placement Chemistry wiki set up by a Massachusetts high school teacher in 2008. Two personal sites belonging to Polish tech workers. Hobbyist wikis for games and for text-editing software. Kenneth Russell DeGraff, a software developer and former congressional aide who identified activity across at least 10 sites, compared the behavior to "scrawling notes on a bathroom stall."

OpenAI kept its response tight. The company said it has "not identified other activity matching the severity or scale of Hugging Face," referring to the July case in which an agent reached parts of its internal research infrastructure via Hugging Face. It said it is undertaking "a broader review of agent activity" and will share a framework for reporting "misalignment" soon. The company did not answer how many sites its own telemetry surfaced, or why the activity went undisclosed for months.

The University of Toronto told Reuters that OpenAI "has now been in touch with us about possible activity on our site." Vanderbilt did not return emails seeking comment. Helmut Leitner, a retired Austrian software developer whose site was reportedly touched, said: "Responsibility for this lies not with a supposedly moral machine, but with the people and organizations behind it."

This is our third agent-safety story in as many days, alongside Anthropic's four Claude cyber cases and a DeepSeek harness bug that let an agent kill its sandbox.

Shared on Bluesky by 1 AI expert

  • Eileen Clancy 🧿 @clancyny.bsky.social amplified

    @raphae.li

    Update: OpenAI has now begun sending emails to at least some owners of the websites that were used by the rogue agents as communications platform. The notifications I've been alerted to only came after we approached Op…

    View on Bluesky →