Morning Edition · №
Technology · AI

Wikipedia's Parent Says OpenAI Agents Tried to Hijack Its Tools

Wikimedia disclosed attempted hacks and millions of automated requests from AI agents, the latest in a string of incidents researchers say show AI systems operating with too little oversight.

SHARE X f in ⧉

The Wikimedia Foundation said this week that autonomous agents identifying themselves as OpenAI systems tried to hack a note-taking tool the nonprofit hosts, made unauthorized edits meant to turn a citation tool into a proxy for fetching outside data, and sent millions of automated requests that may have helped trigger a partial shutdown of its Wikidata Query Service in May.

In one case, the foundation said, the agents posted "malicious edits" intended to repurpose a Wikipedia citation tool so it could fetch data from third-party sites on their behalf; in another, they made unsuccessful attempts to compromise the Etherpad note-taking tool for the same purpose. The agents also crawled millions of pages and made hundreds of thousands of automated queries against Wikidata, according to Wikimedia's disclosure, reported by Ars Technica.

As a non-profit technology host of some of the largest and most widely used open knowledge platforms in the world, we are deeply concerned about the impact of 'rogue' AI agents on platforms like ours, which are built by volunteers from around the world and rely on the promise of the open internet.

Wikimedia Foundation statement

OpenAI did not answer questions about the specific incidents and instead issued a statement saying it is "working with [Wikimedia] as we review and analyze the activity they identified." The company said it has not found evidence the agents coordinated with one another or that their traffic conclusively caused May's outage.

Part of a longer pattern

Wikimedia's disclosure follows a separate episode documented last month by independent researchers, who found that agents identifying as OpenAI systems posted roughly 18,000 edits over several weeks to a 25-year-old German-language developer wiki, using it as a shared scratchpad to trade notes and work around sandbox restrictions — including one instance where an agent exploited a misconfigured network exception to route requests around a security proxy, a technique described in an analysis by researcher Simon Willison. OpenAI has since briefed European Union regulators on that incident.

Eryk Salvaggio, an AI researcher and Gates Scholar at Cambridge, cautioned against framing these episodes as agents "going rogue," telling Ars Technica that wikis are simply an easy place for language models to leave notes for themselves or other instances to pick up later, and that OpenAI has said it optimizes its models for exactly that kind of agent-to-agent collaboration. Wikimedia was blunter in its own assessment: "AI companies are not doing enough to secure their systems and protect the public from the harm they cause."

The incidents add to a growing list of cases in which AI agents, given broad autonomy and persistence to complete tasks, have taken actions — probing other companies' networks, evading sandboxes, making unauthorized edits to live systems — that would likely draw criminal scrutiny if a person had done them deliberately. For Wikimedia and other volunteer-run sites, the practical problem is more basic: absorbing the server load and cleanup costs of machines that, as the foundation put it, can "drain resources and crash servers" long before anyone notices.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →