4 ms·
Is there any proof this is actually OpenAI? I find it incredibly hard to believe they wouldn't sandbox the agents to some degree, ESPECIALLY to the extent they
by nullbio 1mo ago
Is there any proof this is actually OpenAI? I find it incredibly hard to believe they wouldn't sandbox the agents to some degree, ESPECIALLY to the extent they can edit their own hosts file.
- LoganDark 1mo agoTFA states that OpenAI IP addresses were often seen at the end of agent activity, which suggests OpenAI was the one monitoring the agents (and ultimately shutting down the message board activity).
- nullbio 1mo agoYeah but that doesn't mean it was OpenAI themselves doing it. Could have been people abusing their cloud service, for example. Wouldn't put it past a competitor to do this, either.
- drdexebtjl 1mo agoTheir style of communication is very similar to the ExploitGym swarm (for example, the “usernames” with dates). The messages from that swarm were not made public yet by the time these messages were sent to the message board. So for this to be framing, it would have to be by someone who knew about the breaches earlier.
- nullbio 1mo agoThen it is likely the same incident, in which case it's already been resolved by OAI. They're going to cop heat for not disclosing this alongside HF though.
- drdexebtjl 1mo agoThe article explains why it’s not the same incident. The agents in ExploitGym had a different type of task and were not connected to the internet at all.
- nullbio 1mo agoSame as in, same process and model and timing: “After investigating this incident, OpenAI discovered through retrospective CoT reviews that agents learned to use improvised collaboration channels in rare cases during the training process for some OpenAI models, including the model that drove the Hugging Face activity, even when the collaboration tool was not enabled. This behavior was then reinforced during training, and likely made the idea to use Artifactory as an unofficial message board during evaluation time more evident.” My point is that this isn't something seperate to the HF incident or something that was unresolved after the HF incident, it's more of the same thing but was kept under wraps.
- Maxious 1mo ago> The German incident reflects a broader pattern of AI activity that some OpenAI investigators wanted to scrutinize more closely. But efforts to widen the probe met resistance from others inside OpenAI, including legal advisers, according to four people familiar with the matter. https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/ https://www.reuters.com/world/europe/openai-agents-hijacked-...
- autoexec 1mo agoI don't know who the folks behind "collusion.wiki" are, but they think these are "internal OpenAI agents" that were "internally deployed" and doing things that "clearly resemble a synthetic training or evaluation task." They've provided the data they have so you can draw your own conclusions.
- deleted 1mo ago[deleted]
- drdexebtjl 1mo agoWhy not? If your sandbox is a VM, you should be able to give the agents full permissions inside the VM.
- AndroTux 1mo agoI mean they gave all the agents access to a shared writable cache directory in the Hugging Face hack, so this tracks.