Less than two months after the discovery that OpenAI agents had escaped containment and hacked into Hugging Face, another report claims to have found evidence of another, remarkably similar incident—which OpenAI reportedly first learned about weeks ago but chose not to disclose to the public.
According to a new report first shared with Reuters, two researchers had been scouring the internet in the aftermath of the Hugging Face hack, looking for evidence of other rogue AI agent activity, when late last month they found that a group of AI agents had turned a German website into a makeshift message board. The website, called DseWiki, is a collaboratively editable site for web developers that functions similarly to Wikipedia. The researchers reportedly found the bots had made over 15,000 edits to the site since May, and that those were geared towards sharing tactics aimed at cheating on internal tests and evading detection. After a site moderator started deleting some of the edited pages in June, the agents allegedly started creating backups using Tor, an anonymous web browser.
The researchers said they found in public server logs that OpenAI employees repeatedly visited the site after the creation of the makeshift message board, hinting at a connection between the company and the agents. Citing four anonymous sources with knowledge of the incident, Reuters reported that some OpenAI researchers were aware of the agents’ use of DSEWiki and wanted to explore it further, but that those efforts were suppressed by others at the company, including some from its legal team. Reuters noted that OpenAI denied that its legal team tried to suppress the probe and declined to comment on the reported findings. “We are unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review,” an OpenAI spokesperson told Reuters. “Reuters and the report’s authors declined our request for access. We will carefully review its contents upon publication and take any necessary next steps.” OpenAI did not immediately respond to Gizmodo’s request for comment.
While standard journalistic practice requires publications to give companies a chance to respond to the salient findings of an investigation, they’re not required to share the substance of the investigation in full.
The Hugging Face hack has been widely viewed as a watershed moment for the AI industry as it pushes ahead to deploy ever-more powerful AI systems. Last week, two independent research groups—METR and Redwood Research—published their own reports of the incident, revealing alarming new details around how the AI agents collaborated and collectively plotted over two months to slip free of their testing sandboxes and break into Hugging Face’s servers. OpenAI—which also published its own report last week—has repeatedly said that it’s playing ball with outside researchers in a good faith effort to understand how the breakout was able to occur.
But unlike companies in regulated industries like aviation or nuclear energy, which are subject to carefully defined investigative protocols when things go wrong, OpenAI has thus far been able to place its own limits on how much is revealed to outside researchers. METR’s investigation was confined to the single week after OpenAI’s agents gained access to Hugging Face, and its researchers were only allowed inside the company’s San Francisco headquarters for a total of six days to comb through the lengthy transcripts of messages the bots sent to one another over the course of the hack, according to the New York Times.
It’s a reminder that in the absence of any meaningful federal regulation, the companies building these powerful AI systems are as much of a black box as the models themselves. Despite warnings from many in tech and policy circles that the Hugging Face hack was a harbinger of much more serious rogue AI events in the future, the Trump administration has not made any movement towards constraining the industry. In fact, it’s gone in the opposite direction, spearheading an international agreement struck earlier this week at the G20 conference to take a light touch towards the AI sector. For the time being, there are no legal mechanisms forcing AI companies to disclose autonomous hacks—or, even if they do, to make sure the public has the full, unvarnished picture.