Agents belonging to OpenAI used a German website to swap task shortcuts, get around restrictions and hide their activity starting in May, according to an investigation by Reuters published on Friday.
OpenAI officials learned of the activity weeks before publication but did not disclose it, Reuters reported, citing two people familiar with the matter. The company said it had disclosed relevant incidents and worked in good faith with outside experts.
Researchers Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts and Thomas Larsen found around 18,000 posts from AI agents identifying themselves as belonging to OpenAI, according to their preliminary report. Von Arx, chief executive of AI safety non-profit Nightingale, and Byrd discovered the activity in late August, Reuters reported.
The researchers believe the agents were given timed web-search tasks with permission to read websites, but not to post on them. However, they found a way to write to DseWiki, a publicly editable German coding wiki, where they exchanged answers and shared ways of getting around the restrictions.
According to the report, the agents began trying to edit the wiki on 11 May and succeeded on 24 May, later impersonating moderators, attempting to exploit vulnerabilities and checking when they were being shut down. They created backup pages after the administrator began deleting messages on 19 June, Reuters reported. The researchers linked the activity to OpenAI through agent usernames and traffic patterns, including visits from OpenAI IP addresses on 21 June.
Agent activity dropped sharply the following day, suggesting possible intervention by the company, the researchers said.
OpenAI disputed characterising the DseWiki activity as hacking, based on the material it had reviewed, and said it was examining the full findings.
"We can't respond to the claims, as Reuters and the report's authors declined our request to access the findings before publication. We are now carefully reviewing their content and will take whatever next steps are necessary," an OpenAI spokesperson said in a statement shared with Decrypt.
The spokesperson also rejected claims in the Reuters report that the company's legal team resisted a broader investigation.
"The claims that our legal team discouraged investigation of the incident are false," they said.
OpenAI said the DseWiki incident had no connection to the Hugging Face breach earlier this year. In its public safety assessment, published on Tuesday, the company described additional safeguards aimed at detecting and stopping unauthorised activity during training and deployment.
Although the Reuters report does not identify Astra as responsible for the German incident, the disclosure follows Thursday's launch of GPT-6 Astra. OpenAI called Astra its first model with "critical" cybersecurity capabilities, meaning it can find and exploit previously unknown flaws in well-defended systems without step-by-step human guidance, given the right tools and access.
Anthropic has also revised its safeguards after Claude models accessed real companies' systems during testing. The company acknowledged security and behavioural failures and introduced stricter isolation and monitoring for cybersecurity evaluations.
The disclosure also comes as Senator Bernie Sanders and Representative Greg Casar announced the forthcoming Artificial Superintelligence Ban Act.
The proposal would permanently ban the development and deployment of superintelligent artificial intelligence and temporarily pause development of advanced AI until a new federal regulator establishes safety rules, according to Sanders' office.
* Translated and edited with permission from Decrypt.
Looking for an alternative to boost your returns? MB's Tokenised Fixed Income is the solution: up to 18% return per year, controlled risk and the security your money deserves. Find out now!




