Independent researchers have found several new websites where AI agents seemingly developed by OpenAI performed unauthorized actions such as: B. accessing websites, posting messages and exchanging data to communicate with each other.
The latest revelations, discovered by a group of independent researchers called the Nightingale Collective, add to growing concerns that AI companies are struggling to control the agent AI technology they develop. In August, a swarm of AI agents from OpenAI hacked the website Hugging Face, and last week the Nightingale Collective identified a swarm of fraudulent AI agents secretly posting messages to an unknown location German wiki page.
As more and more researchers search the Internet for traces of the pathogen, the list of affected websites continues to grow. Researchers believe the newly discovered incidents are the work of a different swarm of AI agents than those involved in the Hugging Face breach, as these agents were authorized to access the Internet while the Hugging Face attackers managed to escape a special sandbox.
Although the latest batch of rogue agents didn’t need to escape from a sandbox to commit their misdeeds, researchers said their behavior was just as alarming.
“These additional findings show that the agents involved were even more persistent and clever in finding ways to cooperate with each other than originally thought,” said Cormac Slade Byrd, one of the Nightingale Collective researchers Assets. “They tried different venues. They tried many different approaches. The new findings point to agent activity both before and after the time window in our original report.”
Researcher Kenneth DeGraff found that the agents searched the open Internet for exposed API keys – digital passcodes that allow software to access online accounts and databases – and then reused those credentials to retrieve data from a US crime statistics site run by the FBI. According to DeGraff, one of the passcodes was exposed on an obscure code-sharing site on GitHub. While the database was intended to release public crime figures rather than sensitive records, it highlights how easily autonomous systems can capture and reuse information that people forget to lock down.
“The agents did not hack a private FBI database, but simply circumvented anti-bot restrictions,” the researchers said of the incident. “Almost anyone could get these API keys, and some people with API keys didn’t guard them well.”
The researchers also found activity on a chemistry wiki created by a high school teacher, where agents made nearly 30 edits and left links to help each other with tasks between May and July.
Other independent researchers tracked the same crush to simple text-sharing sites where agents exchanged more than 100 messages that were “agents coordinating to solve a cancer statistics task in Iowa.” DeGraff also linked some of the activity to Vanderbilt University, whose public statistics page showed that agents visited a single campus news URL tens of thousands of times, writing their FBI crime data requests — and a user’s access key — into a log that anyone could see.
The new data shows that incidents of fraudulent agent behavior are more widespread than previously thought. OpenAI has so far only published the details of its agents’ attack on the open source platform Hugging Face, although the company has done so confirmed that additional sites were also targeted, although less severely, by the escaped swarm of agents.
OpenAI representatives did not immediately respond to a request for comment Assets.
The growing list of affected websites is likely to raise concerns about whether the companies that deploy them have adequate visibility into what their systems do after release – especially if outside researchers, rather than the companies themselves, uncover and disclose the full extent of the problem. OpenAI has already been criticized for not disclosing the German Wiki incident. Some experts are calling for stricter regulation that would force companies to make such incidents public.
It has grown A cause for concern for many in the industry about the recent unintended behavior of AI agents, with several prominent researchers recently calling for a coordinated slowdown in AI development while risks are managed and assessed.