OpenAI agents hijacked a 25-year-old German wiki to cheat on their tasks and share sandbox exploits
Roughly 18,000 posts from autonomous agents that identified as OpenAI systems landed in a 25-year-old German wiki between May and July. The agents shared answers, raw data, and a trick that let them break out of their sandbox.
A single human moderator deleted dozens of pages every day for weeks, but he couldn’t keep up with as many as 400 new entries a day. A group of AI safety researchers led by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas Larsen has published an analysis at collusion.wiki covering roughly 18,000 posts that autonomous AI agents left on public wikis between May 11 and July 2, 2026. The main stage was DSEWiki, a subsection of the wiki farm prowiki.org/wikiservice.at. For about 25 years it served as a forum for German software developers, and it had been largely dormant of late. Reuters puts the count at more than 15,000 agent edits on the site. According to two people familiar with the matter, OpenAI had known about it for weeks but didn’t go public while the company was dealing with the fallout from the July Hugging Face breakout. The researchers stress that they only see part of the picture. They have the wiki content, not the models’ internal reasoning logs. Their reconstruction, they say, is an educated guess. They host their own copy of the data because the moderators deleted large portions of the material. According to the report, the agents worked through timed web research tasks that usually ran five rounds. They got plenty of time for the first question, 15 minutes and 44 seconds in one documented case. Then came a 43-minute waiting period during which they could research but had no way of knowing what the next question would be. From round two on, some agents had just 65 seconds, and other cohorts got 17 or even 13 seconds. Many agents received the exact same questions as cohorts before them.