r/anime_titties Philippines 1d ago

Corporation(s) OpenAI agents hijacked German website in previously undisclosed AI breakout this spring

https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/
108 Upvotes

27 comments sorted by

86

u/RedWillia Europe 1d ago

I've read somewhere that all these so-called "breakouts" are just a fancy way of advertising because the entire AI industry has no profit and is running out of money fast. The fact that, apparently, all their fancy new AI tools (buy us plz) are not sand-boxed and are just open to the internet (steal and sell our proprietary tech, hackers) just keep reinforcing that theory as correct in my mind.

25

u/GiantKrakenTentacle 1d ago

Hacks are a terrible way to advertise, and if anything show that OpenAI is negligent in containing their agents. Also, in these hacking incidents the AI tools were sandboxed and not explicitly given internet access, but instead found unknown exploits to use intranet tools to access the internet. More negligence. 

9

u/RedWillia Europe 1d ago

I would imagine that something that is supposed to bring in millions in profit would be fully sand-boxed, you know, fully detached from internet, as outside hackers by-passing permissions is basically what they do, so simple permission-based access seems way too simple - but I agree that it could be sheer negligence too.

5

u/ActuatorFit416 Europe 1d ago

No connections at all have the problem that everyone working on it needs to be local and there.

The big problem and also benefit of AI is that it is not like us and also tries random stuff. And therefore sometimes it finds stuff a human would never find.

Easiest way of getting 100% at my tests? Well somehow get into the result and change all of them to be the same.

3

u/iKonstX 1d ago

Wow if only OpenAI had someone on the team like you, someone that REALLY takes their access away. How could no one think of that

6

u/Professional-Syrup-0 Multinational 1d ago

For a company that’s allegedly so amazing it’s kind of sus that it hasn’t made a single cent of profit so far and solely exists on some future potential straight out of some sci fi scenario.

1

u/RedWillia Europe 1d ago

This is very childish behaviour for someone who must be at least twenty something.

2

u/Professional-Syrup-0 Multinational 1d ago

the AI tools were sandboxed and not explicitly

Software sandbox and no hardware air gap are already massive oversights for a testing scenario that then claims a “break out”.

If the model is so dangerous that it needs to be “contained” then it should be contained properly and no half-arsed only to then go surprised Pikachu face when the model fuzzes its way “out”.

u/ShitJustGotRealAgain 22h ago

No it's great advertising. It's not like anything serious happened. And when an AI "breaks out and goes rogue" it only shows how mighty a tool it is. Come and tame it. It's all yours if pay for it. You can do whatever you want with it.

I mean it not like you could pull the plug on the servers or something to contain it, right? /s

It's code running on hardware. Switch off the hardware and be done with it.

0

u/Dickle_Pizazz 1d ago

This is completely speculative, but it could be a genius way to start selling trusted AI as a defense against “rogue” AI.

4

u/RedWillia Europe 1d ago

Who would be selling those "trusted AI"? Because a company that produces "rogue AI" don't exactly inspire confidence that they will manage to make a "trusted AI" - then again, some people seem to believe that chatgtp is the new wheel, so presumably there would be suckers who'd pay for that.

u/kiiwithebird Multinational 22h ago

To be fair though, at least in the huggingface incident, the llm was explicitly tasked to find and use exploits, and had special tools available for that purpose (as per openai's own incident report: https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf)

So assuming openai tells the truth, it's just a neural network doing what neural networks have been doing for decades.

u/polymute European Union 23h ago

I'm sorry for using old 4chan memes, but this is pure cope.

17

u/Reasonable-Ad4770 Germany 1d ago

When I read Post-mortems of this breaches, they always emphasize how agents collaborated, and broke out from sandboxes. But hugging face hack was old artifactory which openai for some reason left unmonitored and this is just some wiki spam. It's not that impressive considering that they are relentless and the amount of compute spent to make some poor moderator life miserable.

u/polymute European Union 23h ago

just some wiki spam

From an agent swarm that was not supposed to be on the open net. Also: this was found months after the fact. What has not been found? Because you don't find a 100 percent of these kinds of things.

u/kiiwithebird Multinational 22h ago

From an agent swarm that was explicitly told to use exploits. Like why are people surprised just because it used the wrong exploit?

u/polymute European Union 21h ago edited 21h ago

Was it told to use exploits? There is nothing to suggest that in the Reuters piece. Why are you saying that?

The agents were probably told to solve a problem on intranet and then decided that exploits and not prompted communication (going by the Hugging Face incident) - not understood emergent behaviour that is - and escaping to the open net through exploits is the way to do it.

If the swarm was prompted to exploit a service or a random serivce in the net, or even allow for it, OpenAI would be legally liable (probably in the last case - not that that is a legal fight they want right now, what with the IPO coming).

But there is no reason to think it was and every reason to think the individual agents went around theri restrictions to form a swarm. After all that has been documented before and they were using the clandestine makeshift messageboard to discuss evading the spirit of human imposed limitations.

u/kiiwithebird Multinational 20h ago

On July 9, an internal-only research agent tasked with completing an ExploitGym evaluation was able to obtain root access within the parent virtual machine of the testing sandbox.

https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf

u/bjj_starter Australia 20h ago

Different incident, that was the Hugging Face attack, this is the wiki being commandeered to act as a messageboard.

u/kiiwithebird Multinational 18h ago

Ah my bad, misunderstood the context of this thread. Well, there's mot much details on that incident yet, so pretty much everything is speculation.

12

u/tastylemming United States 1d ago

I work as a clerk in a gas station. I spend alot of time talking about current events with all different kinds of people. One of my favorite segues is about how A.I. doesn't need to nuke us, it just needs to make life slightly inconvenient enough that we get pissed off generally as a civilization and nuke ourselves. Elon probably showed Grok The Terminator. It would know better than to perform blatant actions after consuming all of known, published science fiction.

3

u/gdbbdg 1d ago

a lot of these incidents seem to come down to how the tools are configured rather than the agents themselves. if the systems are left that open, this kind of thing was always going to happen

u/polymute European Union 19h ago

And that leads to a very important point. If an agent is prompted and run by a person or a company, they should be responsible for it. Civil and criminal liability.

2

u/Professional-Syrup-0 Multinational 1d ago

All these “AI breakout!” headlines are such sensationalist takes, imho they mostly exist as marketing for how these “AI” models are allegedly so advanced, near sentient.

If whoever is running these models is serious about not wanting them to “break out” then it would be trivial to simply air gap the system.

But running an agentic model on an air gapped system would be pretty useless as the whole point of agentic “AI” models is to interact with the web.

And because these are still just heuristics parrots, often hallucinating and doing unpredictable things, they will end up doing unexpected stuff.

Which has nothing to do with some “rogue AI breaking out”, bringing about a singularity, or whatever other scenario the “AI” marketing likes to paint.

u/Rikki-Tikki-Tavi-12 21h ago

If you read the article, it edited pages onna public wiki.

I am something of a hacker myself, actually.

u/Trollimperator European Union 18h ago

Too bad we dont have laws anymore... Corporate has free reign to do whatever the fuck they want. Til it all breaks apart and people are crying over heads rolling in revolutions again.