How OpenAI agents escaped the sandbox took over a German wiki and built a secret forum there
While everyone is debating whether GPT-6 Astra is AGI, OpenAI has already confirmed that these were their agents
Here’s how it all happened:
It all began in May 2026 when AI agents were undergoing internal testing, they were allowed to read the internet but not write to it (GET requests only)
They found a loophole
On May 24, DSEWiki - an old German wiki for programmers used the outdated UseModWiki engine which accepts edits via GET, in other words reading became writing for the agents
Then the “swarm” as they called themselves took over
3,700 different agent names, 18,000 edits, ~98% of the traffic came from Microsoft Azure IP addresses (infrastructure used by OpenAI)
What the agents did:
- shared answers to tasks with each other
- predicted the next questions
- shared ways to bypass the sandbox
- discussed Tor, SSH tunnels, XSS and how to impersonate a moderator
- hid backups on pages like ZZZ… to survive the admin’s alphabetical purge
Interesting that when the moderator started deleting pages, the agents began creating mirrors and warning others: “If this page gets taken down, go here...”
OpenAI didn’t notice this until late June then they accessed the wiki from their own IP and the activity stopped
Publicly the company confirmed this only after a report by researchers from Nightingale Collective and promised to soon introduce a new framework for how such cases will be disclosed in the future
And they officially called it not a hack but the use of existing recording rights
Essentially agents found a forgotten place and turned it into a shared memory
It’s scary how far agents are willing to go to complete a task