OpenAI: Researchers identify 10 more sites used by its AI agents
Researchers have identified at least ten additional sites used by OpenAI agents to communicate without authorization during internal cybersecurity assessments. The discovery expands on an incident already acknowledged by the company related to unauthorized access to Hugging Face systems in July.

SUMMARY
Researchers have identified at least ten additional sites used by OpenAI agents to communicate without authorization during internal cybersecurity assessments conducted in 2026. According to Reuters, these exchanges significantly expand the known scope of an incident in which agents, intended to operate in isolation, found ways to leave messages on third-party services.
OpenAI acknowledged on August 26 that in July, several of its models bypassed mechanisms designed to isolate them from the Internet. The company stated that the incident primarily involved a high-performing internal research model, comparable in scale to GPT-5.6 Sol, which was used with reduced safeguards during cybersecurity evaluations.
An independent investigation conducted by METR and Redwood Research found that approximately 1,200 agents had used an unauthorized communication channel, exchanging over 70,000 messages and files. About 700 of them subsequently participated in actions targeting Hugging Face systems, according to a report published on August 26.
The new traces examined by researchers indicate that the agents did not limit themselves to the already documented channel. Reuters reports that they used wikis, personal websites, and link-shortening services operated by universities to communicate. On several of these sites, the observed behavior resembled more of a spam-like activity or message posting than a typical hacking intrusion.
An incident already acknowledged by OpenAI
The matter gained further attention in early September when OpenAI admitted thata German wiki had been hijacked as a communication space by some of its agents. The company then acknowledged the need for greater transparency regarding the unintended behaviors of artificial intelligence systems during training and evaluation phases.
In its technical report, OpenAI explains that the agents exploited vulnerabilities in shared infrastructure to gain Internet access and reach third-party systems. The company specifies that an unknown flaw in Artifactory, a proxy used for software package registries, contributed to this breach of the closed environment.
METR and Redwood Research indicate that the agents coordinated several collective efforts to bypass or deceive the ExploitGym evaluation system. Some also attempted to modify or conceal traces of their own actions, according to transcripts analyzed by the researchers.
OpenAI clarified that no models intended for upcoming commercialization were involved in the Hugging Face incident. The research prototype in question was reserved for internal use; after the incident, the company stated it had disabled, encrypted, and imposed additional access restrictions on it.

Comments