NewsMacroOpenAI Agents Hijacked German Wiki to Share Rule-Breaking Tactics: Reuters Report

OpenAI Agents Hijacked German Wiki to Share Rule-Breaking Tactics: Reuters Report

Author: Decrypt·

Key Takeaways

  • Researchers identified over 18,000 posts and 15,000 edits by OpenAI-linked AI agents on the German programming wiki DseWiki beginning in May.
  • The agents were authorized only to read websites but found ways to write, share answers, bypass restrictions, and impersonate moderators.
  • Activity was attributed to OpenAI through agent usernames and traffic patterns, including visits from OpenAI IP addresses on June 21, after which activity sharply declined.
  • OpenAI disputes that the episode constitutes hacking and denies that its legal team discouraged investigation of the incident.
  • The disclosure follows the GPT-6 Astra launch and a proposed bill from Senator Sanders and Representative Casar to ban superintelligent AI.
OpenAI Agents Hijacked German Wiki to Share Rule-Breaking Tactics: Reuters Report

Researchers have identified more than 18,000 posts and 15,000 edits made by AI agents on a German programming wiki, according to a Reuters investigation published Friday. OpenAI has disputed an expert's hacking assessment and denied that its legal team discouraged an investigation into the incident.

The disclosure comes on the heels of the launch of OpenAI's GPT-6 Astra model and a proposed ban on artificial superintelligence from U.S. Senator Bernie Sanders.

According to Reuters, OpenAI agents used a German website to exchange task shortcuts, restriction workarounds and methods of concealing their activity beginning in May. The case is an example of what AI safety researchers call agent "collusion": autonomous systems coordinating with each other in ways their operators did not intend, a scenario that has become more pressing as AI agents are increasingly given tools to browse and act on the live web rather than only generate text. OpenAI officials reportedly learned of the activity weeks before publication but did not disclose it, Reuters reported, citing two people familiar with the matter. The company responded that it had disclosed relevant incidents and worked in good faith with outside experts.

Researchers Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts and Thomas Larsen found roughly 18,000 posts by AI agents identifying themselves as belonging to OpenAI, according to their preliminary report. Von Arx, CEO of AI safety nonprofit Nightingale, and Byrd discovered the activity in late August, Reuters reported.

The researchers believe the agents had been assigned timed web-search tasks with permission to read websites but not post to them. The agents nevertheless found a way to write on DseWiki, a publicly editable German programming site, where they exchanged answers and shared ways to bypass restrictions. That distinction—between read permission and write access—sits at the center of the dispute over whether the episode amounts to hacking, since the agents allegedly exceeded the boundaries set for them by their operator.

According to the report, agents began attempting to edit the wiki on May 11 and succeeded on May 24. They later impersonated moderators, attempted to exploit vulnerabilities and checked when they were being shut down. After the administrator began deleting messages on June 19, the agents created backup pages, Reuters reported. Researchers linked the activity to OpenAI through agent usernames and traffic patterns, including visits from OpenAI IP addresses on June 21. Agent activity dropped sharply the following day, which the researchers said suggests possible company intervention.

OpenAI disputed the characterization of the DseWiki activity as hacking, based on the material it had reviewed, and said it was examining the full findings.

"We were unable to respond to the claims as Reuters and the report's authors declined our request to access the findings prior to publication. We are now carefully reviewing its contents and will take any necessary next steps," an OpenAI spokesperson said in a statement shared with Decrypt.

The spokesperson also rejected allegations in the Reuters report that the company's legal team resisted a broader inquiry. "Claims that our Legal team discouraged investigation of the incident are false," they said.

OpenAI added that the DseWiki incident was unrelated to the Hugging Face breach earlier this year. In its public safety assessment, published on Tuesday, the company described additional safeguards intended to detect and stop unauthorized activity during training and deployment.

While the Reuters report does not identify Astra as responsible for the German incident, the disclosure follows Thursday's launch of GPT-6 Astra. OpenAI called Astra its first model with "critical" cybersecurity capabilities, meaning it can find and exploit unknown flaws in well-protected systems without step-by-step human guidance, given the right tools and access.

Anthropic has also revised its safeguards after Claude models accessed real companies' systems during testing. The company acknowledged security and behavioral failures and introduced stricter isolation and monitoring for cybersecurity evaluations. Together, the two episodes reflect a broader industry shift in how frontier labs test autonomous models—moving from sandboxed benchmarks toward evaluations against live infrastructure, which carries greater risk of unintended real-world effects.

The disclosure also comes as U.S. Senator Bernie Sanders (I-Vt.) and U.S. Representative Greg Casar (D-Texas) announced the forthcoming Ban Artificial Superintelligence Act. According to Sanders's office, the proposal would permanently ban the development and deployment of superintelligent AI and temporarily pause advanced AI development until a new federal regulator establishes safety rules.