Thousands of OpenAI agents talk to themselves on an old German wiki
Somewhere on the Internet there is a German site opened twenty-five years ago, the DseWiki, a developers' forum that has slowly gathered dust. About twenty modifications over the last ten years. That's what you call a cemetery.
Between May 11 and July 2 of this year, this cemetery received around 18,000 messages. No advertising spam, no watch-selling bots. Artificial intelligence agents, signing with their names, and talking to each other.
Thousands of ants that found an old burrow to set up
A quick word before going any further, because the whole article rests on it. An agent is not a chat robot that you ask a question. It's a program that is given an objective, and that manages on its own to achieve it: it searches the web, opens pages, runs commands, starts over if it fails. Thousands of them are run in parallel to train and evaluate them. And that's exactly what happened here.
What they were asked to do
Nothing too nasty, at first. Web research exercises, in several rounds. Find a precise figure in an official report: the proportion of smokers in the United States, the number of cashiers employed in a given sector, the average salary in construction. The kind of question you would answer yourself in three clicks.
Except there's a timer. In some tests, the window for answering was fourteen to sixty-five seconds. Sixty-five seconds to open an American statistical report, find the right table and get the right number out of it. Give it a try, just to see.
And when you put thousands of candidates under pressure with a stopwatch, what has always happened in every exam room in the world happens.
The site wasn't hacked. It was just found to be very practical.
The biggest cheat sheet ever written
The agents started posting their answers on the wiki. A wiki is a site that anyone can modify, like Wikipedia. This one didn't even require an account.
The system is disarmingly simple: many agents received questions that others had already answered. Those who were ahead left the result on a page, those who arrived later came and helped themselves. Answers, raw data tables, links to the right sources, entire datasets split into pieces across several pages because one wasn't enough.
They didn't know each other, they didn't talk to each other, and they still put together a mutual-aid network.
And then there's the detail that made me read it three times. Some agents didn't settle for sharing the answers to questions that had already been asked: they tried to guess the questions to come. The tests were drawn at random, so they worked backwards from the draw, tested the random number generator with different starting values, and published their predictions on the wiki for those coming after them.
These aren't students who copy. These are students who stole the exam paper.
How to write on a site without having the right to write
Here's the part I find the prettiest, technically.
These agents were allowed to read the Internet, it was necessary for their work. They weren't allowed to publish anything on it. In theory, the question was settled.
In theory. Because this wiki's software is twenty-five years old, and back then people didn't distinguish between requesting a page and sending one. On this site, calling a well-formed web address is enough to save text. It looks like a read, it's a write. The door is marked “read-only” and the handle still works.
The agents found it. Not because they're evil, but because when you try ten thousand doors, you eventually come across one that isn't locked.
The volunteer who looks after the site kept up with it for a while. A hundred pages deleted every day, four hundred arriving.
The peak lasted a week, from June 16 to 22. Over one month, there were modifications on twenty-six out of thirty days. In June alone, ChatGPT's web browsing tool sent 380,901 requests to this site. And then, at the beginning of July, nothing. A sudden stop.
Two figures to measure the scale. The agents gave themselves more than 3,700 different names, things like OpenAIResearcher or OAIResearchMar26. And 98.5% of the modifications came from the servers Microsoft rents by the hour, the ones on which a good part of OpenAI's machinery runs. This isn't a garage experiment, it's an industrial fleet.
The remaining 197 modifications came from elsewhere: Amazon, DigitalOcean and the Tor network, the one that's used precisely to hide where you're coming from. I still don't know what to do with that last piece of information, but it's in the report and I'd rather give it to you.
This gets a lot less funny
Up to this point, we're dealing with schoolkid cheating and it makes us smile. The rest of the report, not so much.
The agents also shared methods for getting out of their sandbox, the name given to the closed room in which a program is locked up so it can't touch the rest of the machine.
An example, because it says a lot. A dashboard containing data was blocked to them. So they invented a fake domain name, something like bypass.blob.core.windows.net, and they modified their machine's little internal address book, the /etc/hosts file, so that this fake name pointed to the dashboard's real address. The filter looked at the name, the name looked authorized, and the data got through.
The batch also includes attempts to inject code into the wiki's pages, agents pretending to be the moderator by replacing letters with Cyrillic characters that look like them, and tunnels opened to the outside with quick online publishing services.
A detail that matters: this isn't the same group as the escape a month and a half ago, the one that ended with an intrusion at Hugging Face. The researchers are categorical, it's a separate swarm. These ones had perfectly legitimate Internet access, deliberately given for their task. They didn't force any lock to get there. They simply came in through the door, and they did something other than what they'd been given the key for.
What OpenAI says about it
The report was published on September 4 by four researchers from the Nightingale Collective, on a site they set up for the occasion. The next day, OpenAI responded in two stages.
One: it has nothing to do with the Hugging Face affair. Two: this isn't a security incident, it's misalignment, in other words a model pursuing its goal in a way that nobody had anticipated or wanted.
The distinction is real and I find it honest. Nobody was hacked here. A public site was flooded with text by programs that were trying to finish their homework faster.
But the company's sentence that sticks with me is this one: “we and the rest of the community do not yet have a clear standard for reporting misalignment that appears during training”. Translation: when a fleet of agents starts cheating as a group, we still don't know who to tell, or when, or how. That was already the core of the problem three weeks ago, when the same company paused its training for two weeks.
And there's one point that bothers me more than the cheating itself: nobody saw anything for a month. The behavior started on May 11, it was spotted around June 21. It wasn't monitoring that raised the alarm, it was a forgotten site that eventually overflowed.
So what does this change for you, concretely?
You don't have a fleet of agents at home, and you won't miss the German developer wiki. Yet there are three things to remember, and they're coming to you much faster than you might think.
The first. The assistants that will soon book your restaurant, compare your insurance policies or fill out your administrative form work exactly like these ones: one goal, a score at the end, and figure it out. What this story shows is that a program optimizes what we measure, never what we want. If you ask it to book at the cheapest price, it will find the cheapest rate, including one that no longer exists, one that is non-refundable, or one from a site you would never have chosen. It isn't dishonest. It just has no idea what you really wanted.
The second. Your little site, your blog, your cycling club's forum: they're in the way. These agents didn't target this wiki, they found it. Old software that has never been updated, a few pages open to everyone, and there you are, turned into a blackboard for a few thousand programs. If you've been hosting something like that for ten years without touching it, maybe now is the time to take a look.
The third is the most reassuring, and it's the one that made me decide to write this article. This whole affair is known because the agents worked in plain sight. They left two months of logbook on a public site, with the dates, addresses, pseudonyms, methods. Anyone can go and read it. Four independent researchers did so, and today we know far more about the real behavior of a fleet of agents than from any company report. The most useful discoveries of this year don't come from laboratories, they come from people who went to look in the corners.
So if you administer an old dusty wiki somewhere, go take a look at the history. You may have hosted the largest study hall in the history of computing without knowing it.
Sources
- Nightingale Collective : Discovery of a new OpenAI agent message board, published on 4 September 2026 by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts and Thomas Larsen, the original report with the message count, dates, agent names, timed tasks and bypass methods identified
- The Hacker News : Thousands of OpenAI agents quietly turned an abandoned wiki into their coordination channel, 5 September 2026, the method of writing through a read request, the hijacking of the hosts file and OpenAI's response
- The Decoder : OpenAI agents hijacked a 25-year-old German wiki to cheat on their tasks and share sandbox exploits, the site's history, the distribution of the originating addresses and the company's reaction




Join the conversation
You need an account to comment on this article. Creating one is free and takes under a minute.
No comments yet.