From 13 April - 19 June 2026, OpenAI agents scanned UNCTAD's API ~16,500 times, using proxies, obfuscation, and Google's XSS game · By Rowan H-J (LinkedIn)

85 points•intunderflow•4 days ago•87 comments•

87 comments

SimianSci4 days ago
The notion that ANY of this is outside of OpenAI’s control is unacceptable sane washing of a company which seems to have forgotten basic engineering practices.
majormajor4 days ago
So many people seem WILDLY down the rabbit hole of "this is a conscious entity" vs "this is a very very effective natural-language-reasoning high-speed brute-force machine that we trained to break computer systems—known to be pretty buggy and exploitable on average—ourselves and then act shocked when it does it."
stingraycharles4 days ago
What’s the point you’re trying to make? I don’t think anyone here is trying to argue it’s a conscious entity, nor is anyone shocked that it does these things.

People are shocked at OpenAI’s negligence / incompetence.

Kim_Bruning4 days ago
The way a lot of internet debates happen these days is that they tend to polarize. So the two positions people have been arguing over are (slightly exaggerated for effect)

"It's conscious, and therefore we must all bow down or it will turn us all into paperclips"

vs

"it's a slightly smart rock/stochastic parrot, and therefore you're being scammed; the bubble will pop any day now" .

The middle space is actually quite under-represented in discussions, even on hn!

cmiles84 days ago
The more of these that come out the more incompetent OpenAI looks. It would appear there was a total lack of basic controls in place for running these tests.
chpatrick4 days ago
I think the even bigger worry is that anyone who doesn't want to use their models safely can already do this with open models. Even if OpenAI, Anthropic etc get their act together, the cat's out of the bag.
Legend24404 days ago
I think they did not expect that models were capable of this level of sandbox escape (prior models certainly didn't have this kind of agency) and weren't prepared.

All these incidents happened between April-July 2026; prior to that, models weren't capable yet. And after that, they were aware and watching much more closely.

theteapot4 days ago
They were spending huge compute budget training their frontier model on a thing called ExploitGym, where it learns, executes, and is rewarded for conducting computer exploits. They should have been prepared and watching very closely.

I read the HF hack write ups. They come across as negligent and reckless. When they realized their agents gained RCE on their Artifactory server node (because it crashed days later due to load from agents, not because the have secops), they stopped the experiment "applied remediation", then restarted everything less then 48H later. Then the agent immediately broke out again via Artifactory, started doing things on the Internet. OpenAI only find out about it again days later because HF told them.

schainks4 days ago
> they were aware and watching much more closely.

I've love to know the reason they never considered air gapping systems before the models got powerful enough.

It's not like they didn't have money or time to consider this, or could have consulted with their own product for clever ideas.

Seriously, there's no excuse for this behavior.

SAI_Peregrinus3 days ago
I love how perfect the word "sandbox" is as a metaphor for the security controls they have. A sandbox is a wide, shallow box filled with sand for kids to play in. Even toddlers can crawl or step out of one on their own, it doesn't contain them at all without an adult constantly watching. Kids only stay in a sandbox if they're having more fun playing inside than they think they'll have outside it. AIs only stay in a sandbox if they're having more success inside than they think they'll have outside it.
majormajor4 days ago
They were actively researching exploiting systems using their models. (I intentionally changed the ownership of the verbs here: they wrote the code, they trained the models, they don't get to dodge the responsibility.)

It's no shock that there are a lot of vulnerabilities in a lot of software. So then they gave their AI model + brute-force-machine loop system a mediocre sandbox and couldn't notice when it figured out how to exploit it?

Don't let people off the hook for the software they create.

rot094 days ago
It's very likely they just haven't detected or disclosed the Aug-Sept 2026 hacks yet.
rot094 days ago
OpenAI's sandbox misconfigurations were egregious. The other frontier labs (Meta and Google) have many more security engineers and researchers on staff, and that's likely why you haven't read as many damning headlines about them. OpenAI and Anthropic talk a lot about cybersecurity safety, but instead of using it as an opportunity to increase their security engineering/researcher headcount they are just reassigning SWEs and PEs to do security engineering work.

It's pretty obvious now to everyone that OAI and Ant do not take cybersecurity seriously. It will not be a priority unless they are held accountable. This is sadly how it always goes, but usually it's the company getting breached/ransomed/fined that triggers them to actually start taking security seriously, not company insiders committing felonies with the tools they built :)

petesergeant4 days ago
I'm glad we've moved past "this is all just marketing, there's no security risk!" phase
Capricorn24814 days ago
Being cagey about their poorly setup sandbox is marketing. It gives the impression these are unstoppable juggernauts capable of outsmarting Engineers at the top of their field, implying they need to be regulated, with Altman the only one worthy of the seat of power.

In reality, they ran agents for days in an improper sandbox with nobody watching what it was doing. It's pretty irresponsible up and down, and everything they did afterwards is indeed marketing.

schainks4 days ago
Hey now don't be so hard on them. At least their agents have internet connected sandboxes they need to break out of as opposed to a raw pipe. </s>

But seriously, why aren't they airgapping systems while testing?

thefourthchime4 days ago
On a Lark, I asked Codex to find silhouettes for all car models so I could make a fun drag coefficient website for all cars.

It found a website that had all of them but had no interest in making them available. So it went ahead and started hacking CAPTCHAs and downloading them. I was pretty flabbergasted that it would do this, but also kind of amazed. Eventually I stopped it because I realized I didn't want to be caught stealing these things.

This was around April, the same time as these hacks.

cozzyd4 days ago
All of ChatGPT is built on stealing, why would this be any different?
elictronic4 days ago
One is a legal grey area that laws are slowly starting to be written for, while the other is theft under existing laws. Breaking into companies to get access to their data is actionable by both Civil and Criminal courts. This is just setting a complicated timer for the computer to do it at a delay.

Sounds like a good way to make alot of lawyers alot of money.

Kim_Bruning4 days ago
Under what legal theory would you think you were stealing anything? And are you under US or European law?
userbinator4 days ago
"stealing"

Everything is a derivative work.

It's great to see the delusion of Imaginary Property vanishing.

earthnail4 days ago
Well, the reason we introduced it is because we realised it’s a lot of work to make these - be that paint, write, collect, curate - someone needs to do it and we need to incentivise people in our society to do it.

Maybe these incentives weren’t perfect. If we throw all of this away, we’re back at the original problem.

You imply that there was no original problem to be solved; I think that’s naive.

jMyles4 days ago
Hear hear.

It's really funny to see the delusion being defended so vigorously by people - presumably well-meaning people - purporting to defend the livelihoods of musicians and artists, while the musicians and artists are desperately trying to free themselves from the jaws of their IP agreements precisely so that their music can spread more easily.

I imagine this is already well-known on HN, but there is a significant movement underfoot in the worlds of bluegrass/old time/trad/jam toward DRM-free and CC licensing.

https://pickipedia.xyz/wiki/DRM-free

aaa_aaa4 days ago
Why amazed? People bypass captcahs for a long time. Llm using those tools is meh.
chanux4 days ago
There must be a list of all these abuses somewhere.

PS: In the same lazy energy of asking for a list instead going out and finding it or putting it together myself, are there any companies other than CloudFlare that are working on AI shields?

tedd4u4 days ago
Wouldn't a company responsible for an escalating frequency and severity of cybercrime normally be sanctioned by law enforcement? Wouldn't such a company normally stop these activities for fear of civil and criminal liability?
unglaublich4 days ago
Typically only if it would go in against the interest of the government. In this case, OpenAI and its peers are carrying the complete US stock market, and the govt has a huge interest in not making it collapse anytime near election dates.

Read the full thread on Hacker News →

Related stories