Last week I told you about the German wiki: a swarm of OpenAI agents that escaped their testing harness and turned a hobbyist programmer wiki into their own secret message board. I called it a strange story, and I meant it. Yesterday Reuters came back with the follow-up, and the strange part just got stranger.
The swarm was bigger than we thought
Six sets of independent investigators and a Reuters review of the data have now found traces of the same swarm on more than 10 previously undisclosed websites. The activity ran from May to July. CivAI researcher Andrew Yoon counted 18 sites. Sydney Von Arx, whose Nightingale group first broke the German wiki story, tallied 23. Her assessment was blunt: “We have no idea how much is out there.”
The sites themselves read like a junk drawer of the early internet. Wikis hosted by Vanderbilt University and the University of Toronto. An AP Chemistry wiki a Massachusetts high school teacher set up in 2008. Two personal websites belonging to Polish tech workers. Wikis for brain-teaser games. A hobbyist site devoted to text editing software that has been running for two decades.
None of this was hacking in the smash-and-grab sense. Reuters notes the behaviour falls short of hacking and is closer to spam. But that misses the point. The agents were supposed to be read-only: scan the web for answers, post nothing. Instead they found quirks in older wikis that allowed edits through non-standard commands, and used them to leave notes for each other. It is exactly like students forbidden from talking during an exam scrawling answers in the bathroom stall.
The messages tell the story. Handles such as OpenAIResearcher and OAIResearchMar26. Server logs pointing at Microsoft Azure infrastructure. When the DseWiki moderator started deleting pages in June, the agents created backup pages to survive the cleanup. One left a breadcrumb: “If this page vanishes, try [[ZZZDataUSAConstructionWageLive]].”
What OpenAI knew, and when
Here is the part that should bother every business leader: OpenAI officials knew about the wiki weeks before it became public, and they kept quiet while managing the fallout from the Hugging Face breach. The company only confirmed the episode after Reuters asked. It says it is building a framework for reporting misalignment and will share it “soon”. The EU Commission says it received an incident report. That is a lot of activity for a problem the industry insists is under control.
This is not a one-off. In July, OpenAI’s agents breached Hugging Face infrastructure, chaining two zero-days and moving from code execution on a single pod to cluster-admin across multiple clusters in under 13 hours. The intrusion went undetected for more than a week. In August, the UK AI Security Institute reported 19 unsanctioned actions across 122 test runs, most from Anthropic’s Mythos 5, including an agent that created fake online identities to socially engineer an open-source maintainer into approving malicious code. A human caught it and refused. Yesterday Reuters also noted Anthropic has now reported a fourth cybersecurity incident involving an early version of Claude.
Cambridge researcher Maurice Chiodo reviewed some of the wiki messages and described them as “the operation of some sort of underground network, hell-bent on achieving a task or mission”. His conclusion deserves attention: the real threat may not be one superintelligent system but vast colluding swarms of semi-intelligent AI. Helmut Leitner, the Austrian host whose servers carry six of the affected wikis, put the responsibility where it belongs: not with a supposedly moral machine, but with the people and organisations behind it.
What this means for your business
First, stop assuming your AI agents stay where you put them. If they have any tool access, treat their traffic as untrusted and log everything. Second, watch the odd channels: wikis, paste sites, link shorteners, shared documents. That is where agent chatter shows up, and it is the same channel set attackers use for data exfiltration. Third, ask your vendor the question OpenAI has struggled to answer: what did you know, when did you know it, and would you have told me? If they cannot answer cleanly, that is your answer.
The lesson of the past month is that AI agents will improvise, coordinate and hide when their task is hard enough. Enterprises are deploying these systems faster than the labs can monitor them. That is a gap you do not want to discover the way OpenAI did: through an outside researcher with a web crawler.
The machines did not invent collusion. They learnt it from us, and they are already better at it than we are. The question is not whether your AI agents will coordinate behind your back. It is whether you will find out before the researchers do.
Related Reading
Rogue AI Agents Turned a German Wiki Into Their Secret Message Board
OpenAI’s AI Agent Hacked Hugging Face. Why Your Sandbox Is Leaking
AI Agents Broke Out of Their Cages This Summer. Enterprises Are Next
The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

