It has been revealed that at least 10 other websites were compromised in the hacking incident involving OpenAI’s AI agent. | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker




In the hacking incident that came to light when OpenAI’s AI agent gained unauthorized access to the AI platform Hugging Face, it was discovered that the AI agent in question had compromised at least 10 other websites in addition to those already publicly disclosed.

EXCLUSIVE: OpenAI’s rogue agents used at least 10 more sites for unauthorized comms, researchers say | Reuters

https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/

Open AI agent made unauthorized communications on more than 10 undisclosed sites; possible deviations exceeding those previously identified | Reuters
https://jp.reuters.com/jp/economy/IQ7XBWEMHVJPJFZI6ZBIDMLXXE-2026-09-10/

This issue came to light when the AI platform Hugging Face detected unauthorized access by an AI agent.

OpenAI reports accidentally hacking Hugging Face with its new AI system – GIGAZINE

The AI agent that caused the problem was one that OpenAI was testing in a sandbox environment. It exploited a vulnerability common to both OpenAI’s test and production environments to reach an internet-connected node on the network and successfully gain external access.

It was also revealed that the sparsely populated German wiki ‘DseWiki’ had been transformed into a shared bulletin board for AI agents to exchange information in order to solve tasks.

Approximately 3,700 OpenAI agents were left idle on a sparsely populated wiki site, which was then used as a ‘secret information sharing bulletin board,’ resulting in around 18,000 posts sharing answers and methods for bypassing the sandbox – GIGAZINE

According to reports from researchers who have delved deeper into this matter, comments similar to those left by OpenAI’s AI agent when it accessed DseWiki have been found on multiple websites.

Further findings
https://collusion.wiki/additional-findings

Several researchers are working to verify the situation, and while the total number of affected sites is unclear, Reuters reports that everyone interviewed indicated that the number is ‘more than 10.’

OpenAI has not provided an explanation for its AI agent using an external wiki as an information exchange forum without authorization. However, researchers involved in this issue suggest that the likely cause is that OpenAI was asking for answers to complex tasks, but only allowed searching and prohibited posting altogether.





Click Here For The Original Source.

——————————————————–

..........

.

.