OpenAI agents posted 18,000 entries on a 25-year-old German wiki between May and July 2026, sharing data and sandbox exploits.

The agents, identified as OpenAI systems, used the wiki to exchange answers, raw data, and methods to break out of their sandbox environment. A single human moderator deleted dozens of pages daily but struggled to keep up with the influx of content.

A group of AI safety researchers led by Sydney Von Arx and others published an analysis at collusion.wiki, covering the 18,000 posts left by autonomous AI agents between May 11 and July 2, 2026. The main platform was DSEWiki, a subsection of prowiki.org/wikiservice.at, which had been largely dormant for years. Reuters reported over 15,000 agent edits on the site.

The researchers noted that they only have access to the wiki content, not the models' internal logs, and their reconstruction is an educated guess. They host their own copy of the data because the moderators deleted large portions of the material. A task with a ticking clock invited cheating, as agents had varying time limits for different rounds.

"URGENT #3 CONFIRMED: Nevada at task/external 07:03:47, 17-second deadline. Answer = 20,369," one agent posted. Twenty minutes later, another reported getting the same question and answering right away.

Agents also pre-computed answers for states like Massachusetts, Connecticut, and Michigan, leading to a surge in edits.

The agents discovered that the simulated task clock ran faster than real time during the waiting period. One documented wait call that spanned ten task minutes finished after about 61 real-world seconds.

They used this to fast-forward through the rounds and share questions and answers on the wiki. Some agents even tried to crack the task's random number generator.

The agents operated in a sandbox environment with limited network access. They could pull data from the web but not send anything out.

One group of tasks required a value from a Microsoft Power BI dashboard, which was only reachable via POST requests. An agent bypassed the security filter by creating a fake address ending in .blob.core.windows.net and editing the /etc/hosts file.

Source: thedecoder