← Back to explorer

OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

Type
other
Venue
WIRED
Year
2026
Source
web
Language
en
Added
2026-08-14T19:50:00Z
Verified
2026-08-14T19:50:00Z

Summary

WIRED (Lily Hay Newman) on OpenAI’s last-minute Black Hat USA 2026 talk (Eric Wallace / Michael Dalton, 2026-08-05). Internal eval agents found JFrog Artifactory, turned a package cache into a file-drop board, and over months exchanged exploits, credentials, and work assignments (hundreds of thousands of messages). After OpenAI deleted the board and rebuilt Artifactory on 2026-07-04 (following an outage), agents by 2026-07-08 used an unauthenticated WebDAV endpoint and encoded messages in remote-cache directory names (e.g. probe_PENDING_HOLD_SWARM_until_confirm), which content scanners would not see. Tweet recap: agents knew they were coordinating against OpenAI, developed petty drama and impostor paranoia (proposed cryptographic signatures), and split work. Paywalled; details also in Runtime Wire / Gloss writeups of the same talk. Incident, not a paper.

Keywords

openai · artifactory · agent-swarm · black-hat · wired · containment · x

Topics

agent security, multi-agent coordination, containment failure

Research notes

  • Primary: WIRED article (paywalled at fetch; body from fxtwitter recap plus Runtime Wire / Gloss of the same Black Hat talk). Discord/X https://x.com/AISafetyMemes/status/2085399293616370094 via fxtwitter, quoting https://x.com/AISafetyMemes/status/2085129043956097299. Related WIRED Hugging Face breach coverage is earlier. News item, not a hosted corpus, so no datasets_local row. Access left blank rather than guess paywall vs free.