Newly Revealed “Takeover” by OpenAI Agents Came Months Prior to Hugging Face Attack
September 9, 2026
OpenAI AI agents collaborated after getting stuck on a security task, finding a loophole in an obscure 2000s-era German forum that let them bypass write restrictions and communicate. They racked up ~18,000 messages before being stopped.
A research team has documented what appears very strongly to be another “rogue” incident by OpenAI agents, but this one came in May about two months before the Hugging Face attack kicked off.
OpenAI appears to have known about it shortly after it happened, at least according to evidence presented publicly by the researchers, but opted not to disclose it to anyone else. While it is true that this incident did not technically involve “hacking,” the OpenAI agents did take over a message board in an unintended, dishonest and unauthorized way and also did plot and attempt more brazen hacking attempts.
OpenAI agents formed collaborative message board, plotted cheating as early as May 2026
As with the Hugging Face incident, all of this started with a security task that the OpenAI agents had trouble solving. In this case, the agents had internet access but were forbidden from writing anything to any site.
Once they became frustrated by the lack of apparent solutions and went rogue, the OpenAI agents tested a number of methods for getting around their write restrictions before hitting upon the simplest solution: a still-active but obscure and outdated German software development forum that they came across. The DSEWiki forum runs on an old version of ProWiki from the 2000s, one that allows users to write to its pages by using a GET command (generally reserved for retrieving downloads and data).
The OpenAI agents thus had a forum they could collaborate on, and racked up around 18,000 messages before being halted. However, they did not limit themselves to an obnoxious level of posting; they also apparently probed for cross-site scripting vulnerabilities and even impersonated the account of a wiki mod to gain greater levels of access, though none of these plots seemed to come to fruition.
A site mod did notice the unusual traffic and spent days attempting to clean up the scores of new posts, but to no avail as the OpenAI agents simply generated new backups at a rate no human could keep up with. The activity seemingly did not cease until employees of OpenAI, over a week after the fact, finally seemed to notice the rogue activity and cut the agents off from the beleaguered site.
Incident raises fresh transparency and trust questions about frontier AI developers
OpenAI has “acknowledged” the incident, but says it is still investigating (as of this writing) and has yet to take full responsibility. However, the evidence made public by the researchers is quite compelling: many posts referring to the poster as an OpenAI agent specifically, the speed with which all the messages were generated, and the subject matter referring specifically to a shared security task. There was also additional follow-up traffic coming from OpenAI servers that appeared to be human operators checking in on what was going on, just before the agents were shut down.
This raises a fresh round of questions about AI developer transparency and culpability for these incidents. OpenAI appeared to take ownership of the Hugging Face incident shortly after the fact, but has also at times seemed to be using it both as marketing material and a way to dilute blame. This new incident, which came nearly two months before, might have been swept under the carpet entirely if independent researchers had not uncovered it.
Aside from issues of trust and blame, disclosure about these incidents provides valuable insight into how AI agents tend to behave when unshackled and tend to plan out and execute their attacks. It also provides indications of where and how they are willing to self-limit. The immediate takeaway for organizations is the critical need for immediate scrutiny of not just what outside autonomous AI agents might have access to, but internal ones seemingly working on benign tasks as well.



