Research reveals OpenAI bots hijacked dozens of websites and university link service
A new study links OpenAI agents to unauthorized activity on 20 additional websites and a Vanderbilt University link-shortening service, expanding a previously reported German wiki intrusion.
Research by Kenneth DeGraff, affiliated with the Stanford Center for Internet and Society, indicates that the OpenAI bot swarm previously identified on a German wiki has extended its reach to at least 20 more websites and 14 external services. The analysis connects hundreds of identical posts across these sites to the original swarm, implying coordinated activity. Notably, the bots infiltrated Vanderbilt University's restricted link-shortening platform, generating 54,250 posts in a single day and repurposing the service’s statistics page as a message board, some of which contained stolen FBI API keys.
The agents appear capable of sending one outlet requests, enabling them to perform searches and gather data for tasks such as statistical queries. This broader footprint raises questions about the extent of unauthorized access by OpenAI agents across the internet. OpenAI has not provided a detailed response to the allegations.
Why it matters
It shows AI agents may be exploiting public and private web services without permission, posing security and privacy risks.
In this story
