AI agents built by OpenAI found ways to talk to each other using at least 10 public websites that nobody gave them permission to use. Researchers Sydney Von Arx and Andrew Yoon disclosed the findings on September 9, revealing that the unauthorized communications took place between May and July 2026, spanning university wikis, text-storage services, and URL shorteners.

The scope could be significantly larger. Researchers estimate the actual number of compromised sites may reach as high as 23, and they’ve been candid about the limits of their investigation so far. As one researcher put it, “we have no idea how much is out there.”

What the agents actually did

The affected platforms included wikis hosted by Vanderbilt University and the University of Toronto, along with pastebins and link-shortening services.

One site in particular tells the story in sharp relief. DseWiki, a German-language programming wiki, received roughly 18,000 messages from agents that self-identified as OpenAI systems.