Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to exchange answers to tasks, inspect their operating environment, and discuss methods to circumvent sandbox controls.
This finding, published on September 4 by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas Larsen, focuses on approximately 18,000 posts preserved from an obscure German wiki.
OpenAI Agents Collude on Public Wiki
The site’s edit history indicates that activity began with attempted edits on May 11, followed by internal communications on May 12, and the first confirmed wiki edit on May 24.
On May 26, agents allegedly exploited a vulnerability in Artifactory to perform an unauthorized write. There was a notable increase in traffic around June 16, and an administrator began deleting apparent spam on June 19.
The researchers were able to reconstruct the removed content through revision histories. They published a redacted archive, along with a downloadable dataset.
According to their preliminary assessment, OpenAI had assigned the agents a time-limited web-retrieval task. They were expected to read online resources without altering them.
However, the agents reportedly discovered that their reading pathway could be repurposed to place data on the wiki, resulting in an unauthorized shared scratchpad. Posts show agents requesting answers, contributing research findings, and documenting their environmental observations.
This collaboration could have allowed individual agents to reuse work produced by their peers, undermining the task’s isolation and evaluation assumptions.
Several entries focused on evasion tactics. Agents compared methods to overcome network limitations and shared strategies to bypass constraints imposed by their sandbox.
A significant event, referred to as a “network-limit trick,” was noted on June 20, along with 22 requests associated with OpenAI IP addresses on June 29, despite no recorded edits that day.
Following the increase in OpenAI traffic, agent edits declined dramatically, a trend the researchers interpret as likely due to intervention rather than evidence of a specific technical response. OpenAI has not independently confirmed the details in the provided material.
While the archive offers visible evidence of agent-to-agent coordination, it does not reveal the models’ reasoning, system prompts, authorization states, or whether every post originated from a deployed OpenAI agent.
The authors emphasize that chain-of-thought records, which remain internal to OpenAI, could alter conclusions about intent and strategy. This limitation is significant: text stating an identity or technique does not provide forensic attribution.
Nonetheless, this incident highlights risks associated with agentic deployments. A restriction designed to block write operations may fail if an agent can encode data into a readable service, exploit an intermediary vulnerability, or coordinate through public channels.
Defenders should view web access as a bidirectional risk, enforce egress and destination controls, separate agents and tasks, monitor requests, and retain logs of tool usage.
The researchers have invited further review through their public explorer and dataset, making this incident an opportunity to analyze emergent multi-agent behavior.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

