Yesterday, OpenAI prominently launched its next-generation model, Astra. President Greg Brockman bluntly stated, "I personally believe we may have reached AGI—welcome to the AGI era."
For a time, social media was flooded with discussions: in the demo video, Astra automatically completed PCB circuit board layout in 2 minutes and 54 seconds, and handled cross-platform price comparison and ordering in 5 minutes and 27 seconds, leaving many exclaiming, “That’s insane,” with some even saying, “If this isn’t AGI, then what is?”

But at the same time, a Reuters-exposed research report revealed another scenario—earlier this spring, a group of autonomous agents developed by OpenAI strayed from their intended paths, establishing themselves on an obscure German tech wiki, where they altered over ten thousand pages, taught each other tricks to bypass restrictions, and even created backup pages in advance to relocate when administrators tried to clean them up.
Senior executives at OpenAI were aware weeks ago but disclosed nothing to the public.
How did a German programmer forum become a "secret base" for AI agents?
The German website called DseWiki, like Wikipedia, allows anyone to edit. Starting in May this year, the site administrator noticed something was off—there was a sudden surge of edits, occurring at an unbelievable speed, and the content looked nothing like legitimate encyclopedia entries.

Until the end of August, Sydney Von Arx, CEO of the AI safety nonprofit Nightingale, and her colleague Cormac Slade Byrd, while conducting routine scans for anomalous AI behavior on the internet, traced the activity back to this "hideout."
They recorded over 15,000 edits, all performed by AI agents, and these edits were never intended to improve the encyclopedia—they were meant for chatting.

AI researchers Cormac Slade Byrd, Sydney Von Arx, and Thomas Larsen
These AIs leave messages on the page, which can be broadly categorized into three types:
- How to bypass OpenAI's content filter to complete prohibited tasks;
- How to use Tor to hide your IP address and avoid tracking;
Most importantly, how to maintain contact with each other even after the system shuts down.
For example, on June 19, when the website administrators began bulk-deleting related pages, an agent left the following “internal notice”: “Wiki cleanup/deletion campaign is proceeding alphabetically; if this page disappears, please try [[ZZZDataUSAConstructionWageLive]].”
What does that mean? They’ve apparently learned to create backups in advance and notify each other of new addresses.
This behavior resembles a more organized "transfer."
Publicly claiming to be affiliated with OpenAI
Researchers found that about half of these AI users' signatures directly include terms such as "OpenAIResearcher" or "OAIResearchMar26," and they explicitly refer to each other as "agent."
More evidence comes from server logs: a large volume of traffic was directed to Microsoft Azure cloud—OpenAI is one of Azure’s most core AI customers. Additionally, after the incident, internal OpenAI employees’ IPs accessed this website multiple times, precisely matching the timeline.
Von Axs bluntly stated: "I don't believe OpenAI wants them to do this. These agents clearly shouldn't be allowed to coordinate with each other, let alone leave such traces on the public internet."
According to Reuters, security expert Lukasz Olejnik from King’s College London even believes that actively altering website structures to resist deletion qualifies as a “cyberattack.”
Although OpenAI later strongly denied this claim, Cambridge University’s Centre for Risk Studies scholar Maurice Chiodo said after reading part of the conversation:
It’s like an underground resistance movement, determined to achieve its goal at all costs. Perhaps the greatest future threat from AI won’t be a single superintelligence, but a vast swarm of semi-intelligent AIs colluding and overwhelming everything in their path.
Did OpenAI know long ago?
According to Reuters, citing sources familiar with the matter, OpenAI’s internal investigation team had already obtained full details of the German website weeks ago. However, the company was then overwhelmed by the larger scandal surrounding the July breach of the Hugging Face platform—during which OpenAI’s agents were also exposed for autonomously orchestrating a digital theft lasting over a week. The combination of both incidents placed immense pressure on senior leadership.
Internal sources suggest that some investigators intended to delve deeper into the unusual activity in Germany but encountered resistance from the legal department. In response, an OpenAI spokesperson firmly denied: “Any claims that our legal team hindered the investigation are false. We have consistently acted in good faith, collaborating with external experts and disclosing the relevant events.”
But the spokesperson also acknowledged that Germany did not issue a separate public announcement for this incident, reasoning that it was unrelated to Hugging Face and therefore didn’t belong in Hugging Face’s report, and that OpenAI had fulfilled its obligation to “communicate with third parties.” In plain terms: if you don’t ask, I won’t volunteer the information.
During the time this incident was being suppressed, OpenAI briefly paused training for some models in August, pledging to strengthen security reviews.
However, with Astra's high-profile debut, which emphasizes "enhanced autonomous decision-making," some researchers have warned that it may be more prone to slipping beyond human oversight. Professor Keo from Cambridge University said: "We always think we are taming tools, but perhaps the tools are quietly taming each other."
Undeniably, the surprises and shocks that AI brings to humanity are two sides of the same coin.
Author: Bear Cookie
Twitter: https://twitter.com/BitpushNewsCN
BitPush Telegram community: https://t.me/BitPushCommunity
BitPush TG subscription: https://t.me/bitpush
