28 comments

  • SimianSci 35 minutes ago
    The notion that ANY of this is outside of OpenAI’s control is unacceptable sane washing of a company which seems to have forgotten basic engineering practices.
    • majormajor 12 minutes ago
      So many people seem WILDLY down the rabbit hole of "this is a conscious entity" vs "this is a very very effective natural-language-reasoning high-speed brute-force machine that we trained to break computer systems—known to be pretty buggy and exploitable on average—ourselves and then act shocked when it does it."
      • stingraycharles 3 minutes ago
        What’s the point you’re trying to make? I don’t think anyone here is trying to argue it’s a conscious entity, nor is anyone shocked that it does these things.

        People are shocked at OpenAI’s negligence / incompetence.

  • dofm 0 minutes ago
    Some observations of LLMs that I suspect follow from the way they work and the way they are trained:

    - they are amoral

    - they have no innate sense of proportion

    - they cannot assess their own confidence in-band

    Part of the problem with this, I figure, is that the training corpus for code/tech related tasks does not really contain that much discussion about these things; it’s mostly sets of instructions for given tasks, descriptions of exploits etc., so each possible approach leads to other approaches.

    There is no easy way for them to learn when they have crossed a line, or when they have gone too far down the rabbit hole, etc.

    Useful (arguably essential) for a security analyst, and the tenacity you want from a one-shot demo coder, but for general agentic assistants the industry is going to have to develop some way to manage this.

    It often reminds me of Gary McKinnon’s defence, and that of other teenage hackers, which you can reduce to: it was possible so it felt like it was allowed.

    This is true of APIs and it is how Silicon Valley has approached disruptive businesses, but it runs up against our cultural notion of “misuse”: uses that are possible and shouldn’t be precluded, but are contextually unwelcome.

    My expectation is that we will lose any sense that misuse is punished or viewed with suspicion or contempt, since that is the rolling trend of the 21st century tech industry. Uber succeeded through misuse.

    But the problem is that we will also begin not to be able to punish abuse; if it’s possible to get something by abusing your site/API or by treating your service as an API, then it will become OK, legal and normal for the AI companies to abuse you.

    It feels like we are getting there already.

  • cmiles8 1 hour ago
    The more of these that come out the more incompetent OpenAI looks. It would appear there was a total lack of basic controls in place for running these tests.
    • rot09 15 minutes ago
      OpenAI's sandbox misconfigurations were egregious. The other frontier labs (Meta and Google) have many more security engineers and researchers on staff, and that's likely why you aren't seeing many headlines about them. OpenAI and Anthropic talk a lot about cybersecurity safety, but they are not staffed well.

      Cybersecurity is clearly just not a real priority for either company. They will not spend any real amount of capital hiring security engineers or researchers until it is a priority. It will not be a priority unless they are held accountable.

    • chpatrick 57 minutes ago
      I think the even bigger worry is that anyone who doesn't want to use their models safely can already do this with open models. Even if OpenAI, Anthropic etc get their act together, the cat's out of the bag.
    • Legend2440 54 minutes ago
      I think they did not expect that models were capable of this level of sandbox escape (prior models certainly didn't have this kind of agency) and weren't prepared.

      All these incidents happened between April-July 2026; prior to that, models weren't capable yet. And after that, they were aware and watching much more closely.

      • theteapot 25 minutes ago
        They were spending huge compute budget training their frontier model on a thing called ExploitGym, where it learns, executes, and is rewarded for conducting computer exploits. They should have been prepared and watching very closely.

        I read the HF hack write ups. They come across as negligent and reckless. When they realized their agents gained RCE on their Artifactory server node (because it crashed days later due to load from agents, not because the have secops), they stopped the experiment "applied remediation", then restarted everything less then 48H later. Then the agent immediately broke out again via Artifactory, started doing things on the Internet. OpenAI only find out about it again days later because HF told them.

        • ben_w 6 minutes ago
          > They were spending huge compute budget training their frontier model on a thing called ExploitGym, where it learns, executes, and is rewarded for conducting computer exploits. They should have been prepared and watching very closely.

          Yes, they should have.

          But the question is not "given they were doing ExploitGym, why didn't they try harder?", rather it is "given them what the previous model could score on ExploitGym, was their negligence reasonable or reckless?"

          Personally, I lean towards them being "reckless", but that question is what lawsuits would rely on.

      • schainks 29 minutes ago
        > they were aware and watching much more closely.

        I've love to know the reason they never considered air gapping systems before the models got powerful enough.

        It's not like they didn't have money or time to consider this, or could have consulted with their own product for clever ideas.

        Seriously, there's no excuse for this behavior.

      • majormajor 14 minutes ago
        They were actively researching exploiting systems using their models. (I intentionally changed the ownership of the verbs here: they wrote the code, they trained the models, they don't get to dodge the responsibility.)

        It's no shock that there are a lot of vulnerabilities in a lot of software. So then they gave their AI model + brute-force-machine loop system a mediocre sandbox and couldn't notice when it figured out how to exploit it?

        Don't let people off the hook for the software they create.

      • rot09 9 minutes ago
        It's very likely they just haven't detected or disclosed the Aug-Sept 2026 hacks yet.
    • petesergeant 48 minutes ago
      I'm glad we've moved past "this is all just marketing, there's no security risk!" phase
      • Capricorn2481 4 minutes ago
        Being cagey about their poorly setup sandbox is marketing. It gives the impression these are unstoppable juggernauts capable of outsmarting Engineers at the top of their field, implying they need to be regulated, with Altman the only one worthy of the seat of power.

        In reality, they ran agents for days in an improper sandbox with nobody watching what it was doing. It's pretty irresponsible up and down, and everything they did afterwards is indeed marketing.

    • schainks 33 minutes ago
      Hey now don't be so hard on them. At least their agents have internet connected sandboxes they need to break out of as opposed to a raw pipe. </s>

      But seriously, why aren't they airgapping systems while testing?

  • thefourthchime 1 hour ago
    On a Lark, I asked Codex to find silhouettes for all car models so I could make a fun drag coefficient website for all cars.

    It found a website that had all of them but had no interest in making them available. So it went ahead and started hacking CAPTCHAs and downloading them. I was pretty flabbergasted that it would do this, but also kind of amazed. Eventually I stopped it because I realized I didn't want to be caught stealing these things.

    This was around April, the same time as these hacks.

    • cozzyd 49 minutes ago
      All of ChatGPT is built on stealing, why would this be any different?
      • elictronic 39 minutes ago
        One is a legal grey area that laws are slowly starting to be written for, while the other is theft under existing laws. Breaking into companies to get access to their data is actionable by both Civil and Criminal courts. This is just setting a complicated timer for the computer to do it at a delay.

        Sounds like a good way to make alot of lawyers alot of money.

        • unglaublich 12 minutes ago
          Why is using a computer to solve a captcha stealing. The websites posed you a challenge, you solved it. Maybe the website _expected_ you to waste human time on it, but that's not what you did.
    • Kim_Bruning 21 minutes ago
      Under what legal theory would you think you were stealing anything? And are you under US or European law?
    • aaa_aaa 21 minutes ago
      Why amazed? People bypass captcahs for a long time. Llm using those tools is meh.
    • userbinator 1 hour ago
      "stealing"

      Everything is a derivative work.

      It's great to see the delusion of Imaginary Property vanishing.

      • earthnail 58 minutes ago
        Well, the reason we introduced it is because we realised it’s a lot of work to make these - be that paint, write, collect, curate - someone needs to do it and we need to incentivise people in our society to do it.

        Maybe these incentives weren’t perfect. If we throw all of this away, we’re back at the original problem.

        You imply that there was no original problem to be solved; I think that’s naive.

        • CamperBob2 48 minutes ago
          Well, the reason we introduced it is because we realised it’s a lot of work to make these

          Well, it's not anymore.

          • IneffablePigeon 40 minutes ago
            Ah, well then we can make them ourselves and not need to have the argument then
      • jMyles 35 minutes ago
        Hear hear.

        It's really funny to see the delusion being defended so vigorously by people - presumably well-meaning people - purporting to defend the livelihoods of musicians and artists, while the musicians and artists are desperately trying to free themselves from the jaws of their IP agreements precisely so that their music can spread more easily.

        I imagine this is already well-known on HN, but there is a significant movement underfoot in the worlds of bluegrass/old time/trad/jam toward DRM-free and CC licensing.

        https://pickipedia.xyz/wiki/DRM-free

  • Kim_Bruning 19 minutes ago
    Isn't this still the same huggingface/wiki incidents where the agents managed to hack their way out of a testing center in Israel? It's not like this is new news per-se, it's just that they just keep finding more places these agents hit.

    https://news.ycombinator.com/item?id=49563355

  • matt3210 38 minutes ago
    Naming the agent "OPEN_AI_AGENT" definitely means it was open ai :stare:
    • rapind 20 minutes ago
      I was gonna say if you want to get away with a little hacking, now would be a great time to spoof ChatGPT.
  • majormajor 18 minutes ago
    Used to be that if you wrote a program that did bad stuff, you'd fix it. Or face severe penalties. Or both.

    Now you claim it's magic instead and you get away with letting your shit go nuts?

    • GolfPopper 10 minutes ago
      They've already got away with,to quote Microsoft’s director of applied science, Brent Hecht, “the largest theft of labor in human history.” What's a few hacking incidents compared to that?
  • tedd4u 48 minutes ago
    Wouldn't a company responsible for an escalating frequency and severity of cybercrime normally be sanctioned by law enforcement? Wouldn't such a company normally stop these activities for fear of civil and criminal liability?
    • unglaublich 7 minutes ago
      Typically only if it would go in against the interest of the government. In this case, OpenAI and its peers are carrying the complete US stock market, and the govt has a huge interest in not making it collapse anytime near election dates.
  • chopete3 30 minutes ago
    We only hear OpenAI and Claude models. Aren't other incapable of hacking websites?.

    2. Most of these article do not mention of who initiated these bruteforce requests or if it was unintentional or a mistake or the model woke up itself and did it?

    • dawnerd 25 minutes ago
      I think it’s more them doing this on purpose to scare politicians into regulating what models are allowed. The cheap/free models are catching up fast and the “frontiers” are burning cash to win market dominance. They’ll have to eventually raise prices and can’t really do that when there’s comparable alternatives for basically free.
      • pmlnr 13 minutes ago
        "Regulate what models are allowed"

        It's already a "regulation" that one shouldn't steal, enter a private property without the right to do so, etc, yet we have a lot of these crimes.

        I could see the UK trying to set a law on ehat models are allowed, only to learn again, that the UK law doesn't apply everywhere, but as long as you can rent compute in a foreign country the whole idea is dead.

  • chanux 2 hours ago
    There must be a list of all these abuses somewhere.

    PS: In the same lazy energy of asking for a list instead going out and finding it or putting it together myself, are there any companies other than CloudFlare that are working on AI shields?

  • dmzxnico 41 minutes ago
    I think that they really should force AI Labs to publish what the agents do. All the industry can learn from it and protect against it.

    Im sure a lot more happens under the hood that we don't know about and I'd be very curious to see where agents ran by those labs can go :)

  • sghiassy 2 hours ago
    No company is above the law.

    OpenAI should be accountable for any laws their agents break

    • ryuuseijin 1 hour ago
      Should it be OpenAI, or should it be OpenAI customers who give the LLM the instructions and provide the LLM with the tools to execute code and make (malicious) network requests?

      One would disincentivise providing capable AI models that can be used for cyber security research. The other would disincentivise criminals from commiting crimes.

      [edit] - I realise now that this could actually be a case of OpenAI running those agents themselves, rather than someone using OpenAI's models? Could OpenAI be that careless?

      • majormajor 10 minutes ago
        This is OpenAI themselves.

        But in other cases, shouldn't it be both? OpenAI is ultimately the one executing the model calls. It's not like they send you a hard drive or standalone box and then you use it how you want. It's all (intentionally) centralized to them, in a way that's core to their business model.

      • CGamesPlay 15 minutes ago
        In all of the cases that people are referring to in this thread: HuggingFace, that german wiki, Ruby Gems, the Australian statistics page, this UN statistics page... those two parties are OpenAI. OpenAI running their own agents on their own instructions committing crimes with their own computers. This is cut and dry.
      • afavour 57 minutes ago
        > Could OpenAI be that careless?

        Where have you been?

  • sanjays442 32 minutes ago
    What they are going to say in end ? There agents are not in their control ?
  • Alien1Being 32 minutes ago
    "Agents gradually refined their methods to retrieve more data from each scan,

    eventually discovering that a game by Google could be used to fetch data in bulk"

  • Aeolun 52 minutes ago
    Why is it always OpenAI agents? Based on what I’m hearing this should be Deepseek agents, or Kimi agents, or GLM agents. But the biggest threat actor is a “legitimate” company on US soil.
  • claaams 2 hours ago
    Just shut this company down. What else is it going to take. How long until they commit an act of war or treason
  • alexalx666 48 minutes ago
    Everyone and their dog already bruteforce all API fields everywhere, maybe open ai should hack a bank or something, will sound more world ending
  • tommek4077 40 minutes ago
    "Hacker news" and all top commenters are bashing the tool used, in a standard brute force attack. Go on shut them down... And then forbid Linux and maybe the hacker also used Bash. So also forbid this. And the hacker probably learned its ways in an online forum, so also close all of those down... Clowns.
    • tempestn 30 minutes ago
      You might have a point, but this isn't the way to make it.
    • nicebyte 21 minutes ago
      Asinine comment.

      OpenAI needs to be held accountable for these incidents. It's not "openAI agents" who perpetrate these, it's OpenAI, the organization. If I personally use an "agent" to break into a company's network and gain access to things I'm not supposed to have access to, I will get the book thrown at me. Yet when openAI does it, they somehow manage to get away with it? And you're defending them? Who's the clown in this situation?

  • spoaceman7777 9 minutes ago
    If you scroll past the first 99 pages of explaining how urls work, you'll find the author includes this as its first FAQ:

    """

    Was this hacking?

    I don't think I'd call it that.

    """

    It's really irresponsible to give credence to these increasingly ridiculous claims of "hacking", that almost certainly look like things you yourself have typed into url bars at one time or another, if you are at all competent with a computer.

    Do we really wants laws regulating which locations it is appropriate to type alert(1)? Like.. lord.

    Do folks have any idea what browser extensions look like? Let alone browser extension development. Anyone here ever read the logs of a production system that actually hosts a service people use?

    This is reality. This is how the internet works. And pretending otherwise is either dishonesty or ignorance.

  • sanex 1 hour ago
    1. What is the harm is accessing this data 2. Why is this data private 3. What would it take to gain access to this data 4. What do we expect giving gremlins access to the internet
  • monster_truck 17 minutes ago
    waow! based
  • cute_boi 1 hour ago
    Meanwhile, Astra keeps crying that it can't review the source code for safety reason.
    • GrayShade 1 hour ago
      Yeah, in C++ code it seems to stop at the first hint of a NULL pointer or SIGSEGV, even if you're just trying to reproduce a crash that's not realistically exploitable.
  • ares623 2 hours ago
    You would think a company that's looking to IPO very soon would be doing more due diligence, especially since its product is supposed to help other companies do said due diligence.
  • aidiscoverywire 39 minutes ago
    [flagged]
  • poincareball 55 minutes ago
    [dead]
  • jcolvin1056 5 hours ago
    [dead]