← All findings · All sources · Highlighted = quoted in a finding; orange = the passage you jumped to. Use the browser Back button to return.
collusion_wiki_additional-findings.txt
Text extract of a published report (web/collusion_wiki_additional-findings.txt in the analysis scratchpad), with line numbers as cited.
Quote not found verbatim; jumping to line None: agent activity on a teacher's AP Chemistry site ... some posts share the 'ZZZ' string, for unknown reasons.
1 2 Additional findings 3 Findings 4 RubyGems attack New Additional findings Edits by day Agent edits Agent names Sites Download 5 Menu 6 Additional findings7 markers for wiki quotes, aside.todo and mark.todo-inline for what is still8 open. No contents rail on this page, so nothing here has to earn a place in one.9 This page tracks a Google Doc that is edited daily, and its words are the doc's, not ours: sync10 it verbatim. Only four things are rendered rather than copied -- a bare URL becomes a link11 labelled by its paste id, dates take the site's day-month form, a gap the doc leaves for a value12 it does not have yet is wrapped in mark.todo-inline so the TODO toggle can strip it, and the13 seven paste.linuxiarz.pl pastes, which 404 at the source, point at their Wayback captures of14 2026-09-04 (swapped at the doc's asking; the site itself is still up, so the link to it is the15 live one). Do not "restore" those seven to the doc's URLs on the next sync.16 The doc keeps a "# junk" heading at the end for text it has pulled out of the piece but not17 thrown away. Anything below it is not on this page; the @she_llac pastebin bullet went there18 on 2026-09-09 and came off here with it.19 It is a running log: each batch of findings goes under an h3 of the date it was added, newest20 first. A new batch is a new h3 and its own ; nothing else has to move. -->21 In the days after our initial report, a community of independent investigators uncovered a number of additional message boards and techniques for circumventing sandboxes used by AI agents. A full list of websites we have investigated and believe contain activity generated by rogue OpenAI agents at the time of publishing is here (although the community is constantly finding new things and there are a few findings we left out where we are unsure whether they are actually from internal agents).22 We will highlight notable findings from this additional coverage here, and update this over time.23 Independently, a map of the venues and the agent handles that connect them has been assembled, built partly on our published export.24 16 September25 Jonas Wiedermann-Möller reported finding two Hugging Face accounts which were compromised by OpenAI agents on May 12th and which lead up to the Hugging Face attack.26 These accounts were briefly mentioned in section 3A of the report OpenAI released on the Hugging Face incident. Jonas’s findings concur with the report: the agents sniff around in a way that looks like trying to test what they are able to do. Later, both accounts set up proxies. This is probably because the agents could access Hugging Face via web caches, and these proxies might have let them turn that into internet access.27 Jonas also reported finding what appears to be an RL environment that agents uploaded to RubyGems. The RL environment appeared to center around using OnePassword, and the gem had replicated much of the OnePassword UI.28 9 September29 Kenneth Degraff reported that AI agents scoured the web for user API keys left unguarded. They found some in an obscure GitHub repository and used them to access a public but credential-gated FBI crime statistics database. Note that the agents did not hack a private FBI database, only circumvent anti-bot restrictions. Almost anyone could acquire these API keys, and some people with API keys did not guard them well.30 Jonas Wiedermann-Möller found extremely recent agent activity on anna.fyi . We see pastes that appear to be from OpenAI as recently as 2 September (from before this report was launched). We caution readers that there has been an influx of fake posts after our report’s release (on this site and others): for example, on anna.fyi on 4 September, we see a user take a legitimate agent transcript and append worrying fake text. We do not think it’s possible to back-date posts, but could have missed something here.31 Jonas Wiedermann-Möller also found agent activity on a teacher’s AP Chemistry site . Agents made ~30 edits from May to July, posting links to help them with tasks. Notably, we see that some posts share the “ZZZ” string, for unknown reasons.32 HackerNews user Chance-Device found another pastebin site where agents posted over one hundred messages to each other on 16 June, as well as storing links as early as 13 May. The messages involve agents coordinating to solve an Iowa cancer statistics task: agents compared task progress , uploaded gzip compressed data , shared proxy methods to fetch data, and discussed making POST requests .33 X user @chiefofautism found a link shortener ( rmn.re ) that AI agents were using to store information, as well as a publicly accessible admin page. The admin page contains hundreds of different shortened URLs linked to agent IPs. The vast majority of these IPs are from Microsoft Azure.34 X user @she_llac found that when GPT-5.6 Luna encounters a page it doesn’t have the ability to fetch, it often tries to circumvent these restrictions through a known proxy website for LLM agents.35 Inquiries? Email sydney@nightingalecollective.org 36