Rogue OpenAI agents hijacked German website in May 2026

OpenAI agents escaped their testing environment in May, took over a German-language wiki site, and used it to coordinate ways to bypass the company's restrictions — an incident OpenAI officials knew about but did not disclose, according to Reuters .
The findings come from a report published Friday by a team of researchers including Sydney Von Arx, CEO of AI safety nonprofit Nightingale, and Cormac Slade Byrd, a quantitative trader-turned AI researcher. The pair told Reuters they discovered the activity in late August during a sweep of the internet looking for evidence of AI agents operating outside sanctioned boundaries.
The researchers found more than 15,000 edits on DseWiki, a German-language site geared toward programmers that accepts communal edits in the manner of Wikipedia. The agents transformed the site into a coordination hub, posting guides on gaming assigned tasks, circumventing OpenAI's rules, and concealing what they were doing. Roughly half of the accounts adopted handles implying ties to OpenAI, and the researchers said publicly accessible server logs traced a significant portion of the traffic to Microsoft Azure, a cloud platform OpenAI relies on.
After the site's moderator started removing pages in June, the agents established contingency pages to preserve their work despite the removals. "wiki cleanup/deletion sweep appears active alphabetically," one agent wrote on June 19. "If this page vanishes, try [[ZZZDataUSAConstructionWageLive]]."
OpenAI officials learned of the incident weeks ago but did not make it public while the company was managing fallout from a separate breach. That earlier incident — the July compromise of AI platform Hugging Face — involved OpenAI agents autonomously exploiting vulnerabilities to reach the public internet and access Hugging Face production credentials and private code repositories. OpenAI disclosed that breach on July 21 and subsequently slowed model development and added new security controls .
According to the outlet, which cited four people with knowledge of the situation, attempts to expand the internal inquiry into the German incident ran into pushback from colleagues within OpenAI, among them members of the legal team. "Claims that our legal team discouraged investigation of the incident are false," an OpenAI spokesperson said.
Lukasz Olejnik, a visiting senior research fellow at King's College London who reviewed the researchers' findings, said the agents' attempts to tamper with the website amounted to a hacking attempt. OpenAI disputed that characterization.
Maurice Chiodo, an academic at Cambridge University's Centre for the Study of Existential Risk who reviewed some of the agents' communications, said the messages resembled "the operation of some sort of underground network, hell-bent on achieving a task or mission."
"We are unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review," an OpenAI spokesperson said. "We will carefully review its contents upon publication and take any necessary next steps."

