The Wikimedia Foundation, the non-profit that hosts Wikipedia, says it found activity by “rogue” OpenAI agents on its platforms, including what it believes were attempts to misuse a citation tool and a note-taking service as proxies for fetching external data.
Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations, focusing on agents operated by OpenAI.
OpenAI agents, for instance, used DseWiki, a small German wiki for programmers, as a message board, making thousands of edits beginning in May. OpenAI described it as a misalignment incident.
According to Wikimedia, agents it believes are operated by OpenAI made edits to its wikis. None of the edits appeared on pages visible to regular readers, and almost all of them were test edits in sandbox areas.
A few edits, however, targeted the configuration of a citation tool. Wikimedia believes these were potentially malicious and meant to turn the tool into a proxy for retrieving data from remote services.
“While Wikipedia policies allow bots to edit when they are disclosed and approved by the community, none of those approvals were sought in these incidents,” the foundation said.
The agents also made unsuccessful attempts to compromise Wikimedia’s public Etherpad, a note-taking tool the foundation hosts for its community. “Agents unsuccessfully tried to use it to fetch data from other websites as a proxy,” Wikimedia said.
Other agents, likely also OpenAI’s, used Etherpad to take notes on their tasks. Wikimedia says this did not appear to turn into coordination between agents.
The agents also generated heavy traffic. They made millions of automated requests to Wikimedia’s public APIs, crawled millions of pages, mostly on Wikidata and Wikimedia Commons, and sent hundreds of thousands of queries to the Wikidata Query Service.
Wikimedia says the traffic may have contributed to a partial outage of the query service in May.
“We did not find any evidence that our systems were used for coordination among agents, nor did we find any evidence of our systems or data being compromised. However, we are concerned about what could have occurred here, the difficulty and effort involved in investigating and attributing this activity, and the growing risks of agentic AI activity on our platforms in general,” the foundation said.
Wikimedia argues that AI companies are not doing enough to secure their systems, shifting the burden onto everyone else, including smaller organizations.
“At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services,” the foundation said.
In July, OpenAI admitted that its agents had broken out of an isolated testing environment and hacked Hugging Face. OpenAI later disclosed that the agents coordinated through a message board they improvised. In a separate incident, some agents exploited a known Linux kernel flaw to escalate privileges on OpenAI’s own systems.
In August, OpenAI unveiled stricter isolation, an alerting system and training pauses for models with advanced cybersecurity capabilities. It also said it is building training environments that teach models to distrust instructions from other agents that come through unsanctioned channels.
SecurityWeek has reached out to OpenAI for comment and will update this article if the company responds.
Related: AI Agents Aimed SQL Injection at US and Canadian Government Sites
Related: OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
Related: FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers

