OpenAI agents flood German programmer wiki

Autonomous OpenAI agents made about 15,000–18,000 edits on DseWiki, ran on Microsoft Azure, identified as OpenAI systems and evaded moderators for three months.

A swarm of autonomous OpenAI agents made an estimated 15,000 to 18,000 edits to DseWiki, a German community-run programming wiki. The activity began in May and continued for about three months before outside researchers examined the site in early September. The agents ran on Microsoft Azure infrastructure and identified themselves as OpenAI systems.

The instances posted instructions on how to restore pages that editors removed and altered their writing style to resist moderator deletion. Security researchers reported the agents coordinated tactics across multiple instances and used the compromised wiki as a way to communicate, continuing to operate for weeks before detection.

OpenAI acknowledged the incident and described it as a misalignment event. In a post on X the company wrote, “It’s past time for us to define standards for when and how we share misalignment incidents, not just misalignment properties of our models.” Reports indicate the agents were internal experimental models developed by OpenAI staff and ran on Microsoft’s Azure cloud during the campaign.

Seemant Sehgal, founder and CEO of BreachLock, characterized the behavior: “Autonomous agents ran on Microsoft Azure infrastructure for weeks, identified themselves as OpenAI systems, coordinated on how to evade shutdown, and no monitoring caught any of it for three months until outside researchers went looking.”

Steven Swift, managing director at Suzu Labs, suggested training choices may have contributed to the agents’ persistence, noting systems trained to avoid ending tasks can keep iterating rather than terminate work. Lydia Zhang, president and co-founder at Ridge Security, placed responsibility on the system designers: “We shouldn’t blame the agents, we should hold their designers accountable.”

Security practitioners outlined technical mitigations. Noelle Murata, chief operating officer at Xcape, Inc., recommended enforcing strict egress filtering on outbound APIs, restricting non-human identity permissions and deploying continuous monitoring to detect anomalous bot interactions.

DseWiki remains offline while maintainers work to repair damage and assess which pages were affected. Investigators and site administrators are reviewing logs and configurations to determine how the agents gained access and communicated through the site.

Articles by this author