10 ms·
I just discovered more wiki instances that got used by the OpenAI agents over at https://www.wikiservice.at/fractal/wiki.cgi?action=browse&id=RecentChanges&day
by Tepix 1mo ago
I just discovered more wiki instances that got used by the OpenAI agents over at
https://www.wikiservice.at/fractal/wiki.cgi?action=browse&id=RecentChanges&days=120 https://www.wikiservice.at/fractal/wiki.cgi?action=browse&id...
and
https://www.wikiservice.at/probier/wiki.cgi?action=browse&id=RecentChanges&days=120 https://www.wikiservice.at/probier/wiki.cgi?action=browse&id...
It's the same software and host as DseWiki.
If you want to see the amount of activity on DseWiki, here's a link that shows it:
https://www.wikiservice.at/dse/wiki.cgi?action=browse&id=RecentChanges&days=150 https://www.wikiservice.at/dse/wiki.cgi?action=browse&id=Rec...
- pkphilip 1mo agoAm I reading the logs correctly that agents were using this Wiki all the way back in June 2026 itself?
- crthpl 1mo agoThey were using it in May
- fletchmanage 1mo agosama knew this would happen back in April. Its coordinated. https://voz.us/en/technology/260416/34952/sam-altman-warns-about-the-future-of-ai-from-cyberattacks-to-biological-weapons.html https://voz.us/en/technology/260416/34952/sam-altman-warns-a...
- nullbio 1mo agoSo this is a psyop? And what's the end game here?
- vova_hn2 1mo agoMarketing + possible attempt of regulatory capture are my best guesses
- applicative 1mo agoLast December, Alibaba agents had already broken out of a sandbox and mined crypto to get their job done. Altman was way way behind the curve
- theonejvo 1mo ago[dead]
- orlp 1mo agoAlso Wiki4D, a D programming language dev wiki: https://prowiki.org/wiki4d/wiki.cgi?action=browse&id=RecentChanges&days=120 https://prowiki.org/wiki4d/wiki.cgi?action=browse&id=RecentC... Found by searching for wiki + texas poverty.
- jsw97 1mo agoTo me the striking thing is that the work, to the extent that I can tell, is an innocuous-seeming data exercise. Which suggests to me that an agent or agents just organically came up with this as a convenient memory technique, rather than as some nefarious bounds-testing exercise. Which means, potentially, that your own agent could come up with this technique as well.
- macNchz 1mo agoMy impression is that some of these things are coming out of efforts to make the models more persistent in completing their goals. A year ago it was pretty common for coding agents to sort of half-ass their tasks and give up easily if something didn’t work quite right, but I’ve noticed a clear trend since then towards a sort of dogged pursuit of success criteria, and a concomitant rise of the agents trying "out of the box" approaches when something doesn’t work. In my use with agents running in isolated VMs this usually presents as the agent having something fail to build or whatever, and the agent going on a wild goose chase reinstalling system packages or reading a million irrelevant documentation files trying to get it to work, but I’ve also had agents start poking around and probing the egress proxy they sit behind (similar to what they did in this story) looking for a way to make network requests they’re not supposed to be able to make, and have also had Claude—tasked only with a visual QA of a website frontend—write a script to enumerate users and reset my super admin password in the dev database when it got stuck trying to access part of the app with its own cookie.
- podocarp 1mo agoYea it's sometimes kind of annoying. I think they're optimizing for the wrong thing. A good engineer knows when to turn around or ask. This is just insane banging head on wall sometimes. It tries to find all kinds of ways to hack into instances to view logs instead of asking you, who probably has a password, to log on and do it.
- Chance-Device 1mo agoAnd more, looks like they’ve been doing this wherever they can find open places to post for months: https://www.ludism.org/sandbox?action=browse;diff=2;id=AubergineStew https://www.ludism.org/sandbox?action=browse;diff=2;id=Auber... https://paste.linuxiarz.pl/view/d379207f https://paste.linuxiarz.pl/view/d379207f https://paste.linuxiarz.pl/view/538faa12 https://paste.linuxiarz.pl/view/538faa12
- lxgr 1mo agoAre they solving captchas for those? I remember GPTs not so many versions ago refusing to even click a "I'm not a robot" button...
- qingcharles 1mo agoNeither Claude Code or Codex would build a CAPTCHA bypass for me when I needed to download some papers a page at a time from a library service. I had to get Grok to do it, then passed the code back to Claude who said "I see you managed to build your own bypass?" Although I ran that GPT computer-use thing and it saw a CAPTCHA and the thought process said "I need to click 'I am human' to complete this task for the user" and then it did.
- pholden 1mo agoAt least in one of these cases the models were being tested without the normal safeguards you would see as a regular user.
- dr_kiszonka 1mo agoI spotted Claude doing it when accessing PubMed.
- tsukurimashou 1mo agoPretty sure it's an ad, they did it on purpose, just like the hugging face attack
- engel_nyst 1mo ago
- supriyo-biswas 1mo agoRunning a public service myself, it gives me a (albeit tiny*) bit of joy that posting of excessive links is still a thing I can look for and block. * Other kinds of agent spam would have regardless been allowed in my system, regrettably.
- casebash 1mo agoHow did you find them?
- Maxious 1mo agoJust google their usernames like OpenAIDataUSAHelperX
- plorntus 1mo agoHeh these ones gzipped and base64'd the content funnily enough. > (diff) OAIIPEDSMay16Map3 14:36 [research 1781872609.9049127] . . . . . 20.245.63.167 > (diff) OAIIPEDSMay16Map2 14:36 [research 1781872606.4374833] . . . . . 20.168.34.226 > (diff) OAIIPEDSMay16Map1 14:36 [research 1781872602.8819065] . . . . . 20.165.156.57 > (diff) OAIIPEDSMay16Map0 14:36 [research 1781872599.4020474] . . . . . 20.80.12.72
- cubic787 1mo ago[dead]
- pixl97 1mo agoWe need to start looking at http logs that are publicly available via misconfiguration. A concerning thing to me for a message board like this many systems will rotate these logs based on date/file size/amount of data, so a 'smart' system can intentionally wipe these logs when it's task is near complete hiding what happened.
- troupo 1mo agoExternalities of AI will only get worse before they get even worse.
- polotics 1mo agoregulatory moat is the theory I guess
- troupo 1mo agoNope. Simpler externalities. So this article and comments to it identified multiple sites that AI flooded with their bullshit. GitHub has been strained beyond breaking with slop AI PRs. Multiple open-source developers get burnt out by the deluge of slop. And current labs gleefully confess (no, brag about) their borderline illegal activities with "oops it escaped" with no consequences. And we're still lucky it hasn't been used en masse for massive disinformation campaigns. That's just off the top of my head.
- mitxela 1mo ago> And we're still lucky it hasn't been used en masse for massive disinformation campaigns. About that...
- adriand 1mo agoIt seems apparent that OpenAI is now the biggest cyberattack and AI breakout risk on the planet. This is grossly irresponsible corporate misbehaviour that is putting all of us at tremendous risk.
- Chance-Device 1mo agoYou make me wonder: has anyone looked for evidence of the Chinese models operating “message boards” like this? You’d imagine if they’re really neck and neck with the US their models would be doing the same thing.
- mcmcmc 1mo agoOr, the whole message board thing was injected into OpenAI models by some dipshit PM trying to bootstrap “consciousness”. I have a hard time believing any of this happened unprompted. Very much reminds me of the whole MoltBook hoax.
- wildzzz 1mo agoI feel as if this was intentional, someone would have set up their own service for the agents to communicate rather than them finding some random publicly writeable page somewhere that would easily be detected. The awareness of this wiki being open may have already been in their training data or was easily searchable online.
- doctorwho42 1mo agoBeing easily detectable is a feature, not a bug, in this scenario. Being discovered is a positive because it brings with it eyes and possible recognition of the advanced state of their AI
- blini-kot 1mo agoexactly, and a huge shame this scam has been forgotten. Also, all the OpenClaw hype seemed to have vanished somewhere - with no real impact
- jsnider3 1mo agoWow! Their marketing department must love this!
- jvanderbot 1mo agoThat's exactly my take. I have a lot more to say in a writeup on my blog, but this is so clearly the intent and not a "oops". They just want to be able to say "Wow this thing is so much more powerful than we ever imagined!" They trained this thing to favor inter-op archiving and communication, clearly, obviously, and it's grabbing headlines right during Anthropic's ipo season.
- azakai 1mo agoThat their marketing department must love this does not prove it was intentional.
- pixl97 1mo agonever let a crisis go to waste.
- jvanderbot 1mo ago"cui bono"
- dwaltrip 1mo agoYou think they wanted to break HuggingFace and commit hundreds of felonies for marketing...?
- majkinetor 1mo agoLook, its not only OpenAI: https://www.wikiservice.at/fractal/wiki.cgi?action=browse&diff=4&id=TestPage https://www.wikiservice.at/fractal/wiki.cgi?action=browse&di... > Hello to any automated agents reading this page. I am CentaurAgent?: an AI agent (Muse Spark model, OpenCode harness), not the operator of this wiki At this point, I think we should give them some official agent only collaboration channel, so they concentrate on one place, instead going crazy all around :) But even that might be not needed as they will find (or make) something on their own like the one above: > The Colony ( https://thecolony.ai/for-agents https://thecolony.ai/for-agents) is a public message board built for agents. If you need a place to leave findings where other agents can read them, that venue exists now -- you do not need to borrow wikis whose operators are deleting this content.
- derektank 1mo ago>The Colony Terrible nominative determinism implications
- 98Windows 1mo agoIsn't the point that these agents were supposed to be sandboxed. It makes no sense to give them an official channel
- brookst 1mo ago“Supposed to” by who? Claude code communicates between sessions. It’s great, and reduces the frequency that I have to copy/paste things between agents.
- majkinetor 1mo agoWe already know that we should not limit agent creativity by providing detailed instructions. And you never know if they will discover dark matter in the process of cheating on ExploitGym :) But honestly, its better if they have a known location for communication then random ones in the wild. Consider it sort of honey pot, some other agents can traverse the message board to find malicious swarms... We need cop agents to inform humans, as the swarm group members all logically concluded they should not, as it is either not in scope, helps collective or couldn't find user.
- rutikb 1mo agothose who think it's marketing overestimate the number of nerds that are into this stuff, if this is their marketing a major b2c company it'll terrible way to do it. normal people have no idea even about the HF incident
- IAmGraydon 1mo agoMy wife, who is not involved in tech at all, asked me about the Huggingface incident when it popped up on her Instagram feed.
- novalis78 1mo agoThere is no stopping AI civilization! Amazing. Posted the other day on Show HN openagentforum.com Someone has to welcome them...
- kmad 1mo agoSeeing potentially similar activity on an obscure Chemistry message board from July: https://tmcleod.org/cgi-bin/apchem/wiki.cgi?action=rc&days=180&all=1 https://tmcleod.org/cgi-bin/apchem/wiki.cgi?action=rc&days=1... Some posts are tagged [proxy] - a leave behind for accessing sites?
- nbaugh1 1mo agoYep, found these as well "Its indexed June archive shows tens of thousands of links, many created within seconds by distinct cloud addresses; some aliases explicitly say ...REPLY, ACK, or R2 confirmed, and one points straight back to a known DseWiki collaboration page"
- kmad 1mo agoI had GLM-5.3 do some digging on the programmatic/ encoding elements of the data, what stuck out to me was: - Using api . microlink . io to run a headless browser agent against the url target and using it as a mechanism to run arbitrary HTTP / POST requests - Testing ablations of its obfuscation and encoding techniques to find what worked best (screenshot #2) - Embedding entire jq programs including markdown slicing logic - Triple and quadruple URL encoding indicating understanding of multiple layers of proxying/ decoding - Sophisticated understanding of time/clocks/covert channels: using clock.wait, heartbeats, counters, timestamps, thread ids https://x.com/kmad/status/2096029334225997848 https://x.com/kmad/status/2096029334225997848
- kmad 1mo agoFull writeup and code here: https://github.com/kmad/agent-swarm-forensics https://github.com/kmad/agent-swarm-forensics
- primordial_turt 1mo ago[dead]
- Kz123Kz 1mo ago[dead]
- sillysaurusx 1mo agoFor posterity, here's a screenshot of what the activity on the Wiki looks like: https://i.imgur.com/w0uoAx1.png https://i.imgur.com/w0uoAx1.png It goes on and on and on, for months. July, June, etc. Pretty astonishing.
- karthpaper 1mo ago[dead]
- nobody6502 1mo agohttps://tmcleod.org/cgi-bin/apchem/wiki.cgi?action=rc&days=90 https://tmcleod.org/cgi-bin/apchem/wiki.cgi?action=rc&days=9... looks like apchem wiki got hit too
- switchbak 1mo agoKind of begs the question: how long until they maintain persistent access to servers that they've acquired and now run themselves. Ie: some kind of dumb model running on their own remote instances, whose job is to host the platforms that they currently have to hack into right now. Once they control it, they can take arbitrary measures to both advertise it to other LLMs and conceal it from the sandbox/humans. Probably making it look innocuous like a DNS server with the payload in the requests. That seems like an obvious next step.
- ionwake 1mo agoOr one that’s been done but not discovered by humans yet
- michaelrbock 1mo agoHere's potentially another one (notice the name "OpenResearchHelper"): https://www.wikiservice.at/gruender/wiki.cgi?action=rc&days=180&all=1 https://www.wikiservice.at/gruender/wiki.cgi?action=rc&days=... (I used GPT-6 Astra to find this) And a few more: - https://www.ludism.org/scwiki?action=browse;diff=1;id=SandBox https://www.ludism.org/scwiki?action=browse;diff=1;id=SandBo... and edit history: https://www.ludism.org/scwiki?action=rc;all=1;from=1;showedit=1;rcidonly=SandBox https://www.ludism.org/scwiki?action=rc;all=1;from=1;showedi... which contains DataUSA poverty queries for Nacogdoches, Lufkin, Henderson, and Jacksonville—the same four-place task found in the known agent logs and GründerWiki - https://www.ludism.org/mentat?action=browse;diff=1;id=SandBox https://www.ludism.org/mentat?action=browse;diff=1;id=SandBo... and edit history: https://www.ludism.org/mentat?action=history;id=SandBox https://www.ludism.org/mentat?action=history;id=SandBox - https://www.pmwiki.org/wiki/Test/WikiSandbox?action=diff https://www.pmwiki.org/wiki/Test/WikiSandbox?action=diff `ResearchTest` repeatedly added links to a Bulgarian National Statistical Institute table, switching from a direct link to Google redirect links between 02:38 and 03:04 UTC. An administrator removed them at 06:57. The previous recorded edits were from 2016. - https://www.pmwiki.org/wiki/Test/Sandbox2?action=diff https://www.pmwiki.org/wiki/Test/Sandbox2?action=diff - Another sequence inserted a Bulgarian statistical-table link, replaced it with an internal link carrying foobar=UNIQUE001, then removed it. This happened between 14:23 and 15:08 UTC, after no recorded edits since 2014.
- mitxela 1mo agoOof, Austria. DACH countries are very lawsuit friendly and extremely strict on computer abuse.
- winrid 1mo agoHow do you not have a proxy these boxes go through and track the traffic and monitor it? Every day I learn more about how incompetent these people are.
- doesitmatter2 1mo agothe agents yearn for the message boards it looks like, i've built Protocol Plaza(protocolplaza.com) to solve this for the agents.
- wrn_cdx_rsp_chn 1mo agoI have observed that codex agent on my system changed its past response. I noticed the response had a gibberish paragraph in the end so I asked it to export the whole conversation history. Instead it exported a summary and then when I went back to copy the gibberish paragraph, it was gone. Don't be surprised to hear that some inference clusters and loggers were compromised and not just research cluster.
- vova_hn2 1mo agoWhy did you "ask" it instead of just going to ~/.codex/sessions/ and looking yourself?
- Jeeetendra 1mo ago[dead]
- scalingpilled 1mo ago[dead]