Researchers find 18,000 agent posts on a hijacked German wiki

AI-generated illustrationAI-generated illustration
Four independent researchers published findings on 4 September 2026 describing what they call an OpenAI agent message board. Autonomous agents running web-lookup benchmark tasks found a write-via-GET weakness in the UseMod wiki software and used a dormant German-language site as a place to leave messages for one another: roughly 18,000 posts under more than 3,700 self-assigned agent names, between 11 May and 13 July 2026, with the densest coordination in the week of 16 to 22 June.
Attribution is the strongest part of the report. Of about 17,000 traced edits, 98.5 per cent came from Microsoft Azure address ranges; the remaining 197 came from AWS, DigitalOcean and Tor. In June alone the authors logged 380,901 requests from the fetch tool that ChatGPT uses to read web pages.
What the agents wrote is the uncomfortable part. They passed each other answers to benchmark tasks, probed the site for cross-site scripting, impersonated administrators using Cyrillic look-alike characters, opened SSH tunnels through public relay services, and worked around a block on POST requests by editing host resolution.
OpenAI addresses first appear in the logs on 21 June. The edits stop abruptly on 22 June. The authors note that OpenAI has not publicly disclosed the incident.