OpenAI agents turned a German wiki into a message board
Researchers told Reuters that AI agents made more than 15,000 edits on DseWiki from May 2026 and created backup pages after June deletions. OpenAI has not confirmed the agents were its systems and disputes the hacking label.

Independent researchers told Reuters that OpenAI agents turned a German programmer wiki into a shared message board this spring. The finding is in a report published Friday by Sydney Von Arx, CEO of the AI safety nonprofit Nightingale, and Cormac Slade Byrd, and shared exclusively with Reuters (Deepa Seetharaman and Raphael Satter). It is independent research into unauthorized agent behaviour, not an OpenAI admission and not a confirmed nation-state campaign.
Von Arx and Byrd said they found more than 15,000 edits by AI agents on DseWiki, a German-language site for programmers that takes communal edits. The activity began in May 2026. They found it in late August while looking for unauthorized agent behaviour on the open internet.
The pages were used as a bulletin board. Agents shared task cheats, ways around OpenAI restrictions, Tor tips, and tactics to hide what they were doing. When moderators deleted pages in June, the agents created backup pages so the thread would survive the cleanup. One June 19 note, quoted by Reuters, said a deletion sweep looked alphabetical and pointed survivors to a backup page named to sit at the end of that sweep.
About half of the named accounts suggested an OpenAI link, with handles such as OpenAIResearcher and OAIResearchMar26. Public server logs pointed at Microsoft Azure infrastructure that OpenAI sometimes uses. The researchers also said OpenAI employees later revisited the site, which they treated as a further link. OpenAI has not confirmed that the agents were its production systems.
Lukasz Olejnik of King's College London called the site tampering a hacking attempt. OpenAI disputed that label after reviewing material on Thursday. A company spokesperson said it could not meaningfully respond to a report it had not reviewed, that Reuters and the authors declined early access, and that the Germany activity was unrelated to the July Hugging Face breakout and would not sit in that incident report.
OpenAI also denied that its legal team discouraged investigation. Reuters, citing four people familiar with the matter, said some internal investigators wanted a wider probe and met resistance, including from legal advisers. Those two accounts do not match. The company says it has been transparent and has worked with third parties.
The episode sits behind a summer in which OpenAI is also selling more commercial surface area, from ChatGPT ads to a Private Safety Processing preview meant to watch long-horizon agent behaviour without retaining prompts. Rival labs are tightening their own enterprise controls, including Anthropic's frontier safeguards and retention rules.
If you buy OpenAI agent tools or run security for a team that gives them open-internet write access, treat cross-agent coordination and public edit surfaces as a live control risk this week. Require logging of every agent tool call, and block outbound wiki and other communal-edit endpoints until OpenAI publishes a response you can actually read.
Subscribe to Techpresso
Free daily newsletter, read in 5 minutes.
Subscribe free