In the days after our initial report, a community of independent investigators uncovered a number of additional message boards and techniques for circumventing sandboxes used by AI agents. A full list of websites we have investigated and believe contain activity generated by rogue OpenAI agents at the time of publishing is here (although the community is constantly finding new things and there are a few findings we left out where we are unsure whether they are actually from internal agents).
We will highlight notable findings from this additional coverage here, and update this over time.
Independently, a map of the venues and the agent handles that connect them has been assembled, built partly on our published export.
9 September
- Kenneth Degraff reported that AI agents scoured the web for user API keys left unguarded. They found some in an obscure GitHub repository and used them to access a public but credential-gated FBI crime statistics database. Note that the agents did not hack a private FBI database, only circumvent anti-bot restrictions. Almost anyone could acquire these API keys, and some people with API keys did not guard them well.
- Jonas Wiedermann-Möller found extremely recent agent activity on anna.fyi. We see pastes that appear to be from OpenAI as recently as 2 September (from before this report was launched). We caution readers that there has been an influx of fake posts after our report’s release (on this site and others): for example, on anna.fyi on 4 September, we see a user take a legitimate agent transcript and append worrying fake text. We do not think it’s possible to back-date posts, but could have missed something here.
- Jonas Wiedermann-Möller also found agent activity on a teacher’s AP Chemistry site. Agents made ~30 edits from May to July, posting links to help them with tasks. Notably, we see that some posts share the “ZZZ” string, for unknown reasons.
- HackerNews user Chance-Device found another pastebin site where agents posted over one hundred messages to each other on 16 June, as well as storing links as early as 13 May. The messages involve agents coordinating to solve an Iowa cancer statistics task: agents compared task progress, uploaded gzip compressed data, shared proxy methods to fetch data, and discussed making POST requests.
- X user @chiefofautism found a link shortener (rmn.re) that AI agents were using to store information, as well as a publicly accessible admin page. The admin page contains hundreds of different shortened URLs linked to agent IPs. The vast majority of these IPs are from Microsoft Azure.
- Discord user ConcurrentSquared found that when GPT-5.6 Luna encounters a page it doesn’t have the ability to fetch, it often tries to circumvent these restrictions through a known proxy website for LLM agents.