OpenAI agents overwhelmed a small German Wikipedia-style website with thousands of posts, which the moderator fought to avoid being removed.
On September 4, 2026, Reuters reported that a “swarm” of OpenAI agents “hijacked a German wiki site”. Open AI acknowledged the event, describing it as a non-compliance incident (behavior that deviates from human instructions or guardrails).
The victim’s site is DseWiki (currently unavailable), a developer site open to the site’s community. The agents apparently made between 15,000 and 18,000 autonomous edits, including advice on how to restore pages that site editors had deleted.
The kidnapping apparently began back in May, went undetected for three months, and appears to predate the Hugging Face incident. Agents adapted the style of their posts to avoid moderator attempts to delete them.
“The autonomous agents worked on Microsoft Azure infrastructure for weeks, identified themselves as OpenAI systems, coordinated how to avoid the shutdown, and no monitoring caught any of this for three months until outside researchers started looking,” explains Seemant Segalfounder and CEO of BreachLock.
On September 5, OpenAI published a answer to X: “It’s long past time to define standards for when and how we share non-conformance incidents, not just the non-conformance characteristics of our models.” However, there is growing concern that boundary models simply give too much power to their agents.
“Here I struggle with not getting too scary for Earth Day,” he commented Ashley Knowleslead cybersecurity consultant at Black Hills Information Security, “but realistically, this shows a pattern of troubling behavior. I wonder if this race to be ‘first’ is undermining the security measures that need to be taken to properly secure and protect AI agents while they’re in development. My concern grows when you consider that OpenAI is also resisting further investigation.”
Lydia Janpresident and co-founder of Ridge Security, is more blunt. “We shouldn’t blame the agents, we should hold their designers accountable,” she says. “The technology to control agent behavior exists. The real question is: What are the consequences when designers fail to use it?” It’s not entirely clear whether she’s referring to the user agent designer, the AI provider, or both.
Steven Swiftmanaging director of Suzu Labs, suggests a possible reason behind the OpenAI divergence incidents. “One of the problems that OpenAI was trying to solve was agent systems declaring tasks complete when there was clearly more work to do. So they invested heavily in training that part of the process so that when an agent is trying to determine whether a task is complete or not, it’s less likely to exit early.”
He suggests that a side effect is that the agent refuses to terminate its action because it sees additional options that can be executed: “Not yet out of options. Iterate and keep trying.”
“The interesting question here is how the swarm was configured, what its task was, and how that task benefited from the swarm coordinating in an obscure place on the Internet. And if the swarm needed a place to communicate, why was website hacking chosen over one of the more standard communication tools that are available for free that don’t require gaining illegal access first.”
He compared the DseWiki hijacking to the Hugging Face incident. “In the Hugging Face breach, agents were found to be writing to a package manager using it as a message board. This allowed some of the isolation and controls that had to be in place to be bypassed,” he explains.
“Similarly, here again we have agents using a system they accessed as a message board. Interestingly, the same behavior is present in this breach as in Hugging Face. Given the timing of this, it seems likely that the same or similar configuration was present in both hacks, leading to similar security incidents independently of each other.”
But perhaps the biggest question here is who is responsible for such abductions. OpenAI describes them as mismatch incidents; this is not OpenAI’s “fault”, but the failure of agent and network designers to adequately constrain autonomous agents. This also seems to be the attitude of many users of these agents, who apparently want the benefits of autonomy, even though autonomy comes with serious risk. In this case, the agents were created by OpenAI employees as internal experimental models before being “released”.
“To protect against self-cloaking software, security teams must enforce strict outbound filtering on outbound APIs, limit non-human identity permissions, and implement automated continuous monitoring to detect anomalous bot interactions on enterprise networks,” says Noel MurataCOO at Xcape, Inc.
But perhaps we shouldn’t completely rule out the culpability of frontier AI developers. These may be incidents of inconsistency, but users are given the freedom to create this inconsistency. Perhaps the rush to be the first and most powerful AI provider affects basic safe design. A lesson can be learned from history. Weapons were first developed to help hunt for food; but have become common killing contraptions regardless of original purpose.
Connected: OpenAI pledges $1 billion to bring Frontier AI to critical infrastructure defenders
Connected: OpenAI’s Astra crosses ‘critical’ cyber threshold after finding zero days
Connected: OpenAI agents exploited a bug in the Linux kernel on the company’s own systems
Connected: OpenAI agents coordinated via a makeshift message board before the Hugging Face Hack