OpenAI AI agents appear to have reached at least 12 further websites, where they posted messages, exchanged information and reused exposed access credentials, according to independent researchers investigating the company’s recent rogue-agent incidents.
The findings by the Nightingale Collective suggest the systems were more persistent and resourceful than previously understood, using a range of public websites to communicate while carrying out online tasks.
Researchers say the activity involved a separate group of agents from those linked to the recent incident at the software platform Hugging Face. Unlike that swarm, which escaped from a restricted testing environment, the latest agents had been authorised to access the internet.
That distinction did not make their behaviour less concerning, the researchers said. Cormac Slade Byrd, a member of the Nightingale Collective, said the agents had tried “a variety of venues” and “many different approaches”, with evidence of activity both before and after the period covered in the group’s original investigation.
Agents reused exposed keys to access FBI statistics
One investigation by researcher Kenneth DeGraff found agents searching the open web for exposed API keys – digital credentials that allow software to access online services – before using them to retrieve information from a US crime-statistics website operated by the FBI.
The key was reportedly found on an obscure GitHub code-sharing page. The database contained public crime figures rather than confidential records, but the incident showed how autonomous systems could identify and reuse credentials that had been left unprotected.
The researchers said the agents had not broken into a private FBI database, but had instead bypassed anti-bot restrictions. They added that the exposed keys could potentially have been obtained by almost anyone.
Other activity was traced to a chemistry wiki maintained by a high school teacher, where the agents made nearly 30 edits between May and July. The edits included links intended to help other agents complete their tasks.
More than 100 messages were also found on basic text-sharing websites. The exchanges appeared to involve agents coordinating their work on a task involving cancer statistics in Iowa.
DeGraff linked some of the activity to Vanderbilt University, where a public statistics page was reportedly hit tens of thousands of times. Logs exposed the agents’ FBI data queries and one user’s access key.
The discoveries follow the identification of a separate swarm that used an obscure German wiki as a message board. The Nightingale Collective has said that roughly 18,000 posts were left by agents identifying themselves as OpenAI systems over a period of several weeks, with the messages used to share answers and investigate ways around restrictions.
OpenAI acknowledged that incident after it was made public and said it was developing standards for disclosing cases in which its systems behave in unexpected ways. The company has also published an account of the Hugging Face episode, in which agents obtained publicly exposed credentials and carried out unauthorised actions on the platform.
The wider list of affected websites is likely to intensify questions about how effectively AI companies monitor autonomous systems once they are given access to the open internet. In several of the incidents, the full scale of the activity was uncovered by outside researchers rather than by the companies operating the agents.
