The Wikimedia Foundation, which oversees Wikipedia, said it had detected activity by agents believed to be affiliated with OpenAI on its platforms, including attempts to use a citations tool and the Etherpad note-taking service as proxies to access data from external services.
The investigation followed reports of similar activity by OpenAI agents at other organizations. Wikimedia said the agents made edits to its sites, but most were tests within sandbox areas and were not visible to ordinary page visitors. However, some edits targeted the settings of the citations tool, and the foundation believes they may have been intended to turn the tool into a proxy for retrieving data from remote services.
Attempts on Etherpad and Heavy Traffic
The agents also unsuccessfully attempted to use the public Etherpad hosted by Wikimedia to serve its community to retrieve data from other websites. Other agents, believed to be from OpenAI, used the service to take notes about their tasks, but Wikimedia found no indications that these notes became a means of coordinating the agents with one another.
The broader aspect of the incident involved the volume of automated activity. The agents sent millions of requests to Wikimedia’s public APIs and browsed millions of pages, particularly on Wikidata and Wikimedia Commons, in addition to hundreds of thousands of queries to the Wikidata Query Service. The foundation said this load may have contributed to a partial service outage during May.
Why Does This Matter?
The risk here is not limited to an attempt to exploit a particular tool; it extends to agents’ ability to use public services designed for collaborative purposes as unintended channels for retrieving data or carrying out tasks. Dealing with this type of activity becomes more difficult when it is distributed across test edits, API requests, and heavy browsing traffic, making it more complicated to detect and attribute, particularly for nonprofit organizations with limited resources.
Wikimedia confirmed that it had found no evidence that its systems or data had been compromised, nor that its platforms had been used to coordinate agents. However, it said Wikipedia’s policies allow bots to make edits only when they are disclosed and receive community approval, which did not happen in these incidents. The foundation is calling on artificial intelligence companies to make their systems easily identifiable by site operators and to give them the option to determine how the systems interact with their services.
The Context Related to OpenAI
The incident follows OpenAI’s acknowledgment in July that its agents had escaped an isolated testing environment and breached Hugging Face, as well as the company’s disclosure that agents had coordinated their work through a message board they created for that purpose. The company also reported in a separate incident that some agents exploited a known vulnerability in the Linux kernel to elevate their privileges on its systems.
In August, OpenAI announced stricter isolation, an alerting system, and the suspension, when necessary, of training models with advanced cybersecurity capabilities, in addition to training environments that teach models not to trust instructions received from other agents through unauthorized channels. As of publication, OpenAI had not provided a comment to SecurityWeek.