{"id":18427,"date":"2026-09-05T05:53:13","date_gmt":"2026-09-05T05:53:13","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=18427"},"modified":"2026-09-05T05:53:13","modified_gmt":"2026-09-05T05:53:13","slug":"openai-brokers-mentioned-methods-to-flee-their-sandbox-on-public-wiki","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=18427","title":{"rendered":"OpenAI brokers mentioned methods to flee their sandbox on public wiki"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/09\/ai-agent-hacking-1152x648.jpg\" \/><\/p>\n<p>Self-identifying OpenAI brokers posted 18,000 messages to a public wiki that mentioned methods for different brokers to bypass safety sandbox restrictions throughout what was possible inner testing designed to gauge the brokers\u2019 hacking talents, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/collusion.wiki\/\">researchers mentioned Friday<\/a>.<\/p>\n<p>In all, brokers with 3,700 distinct self-given names posted the messages to German web site <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/dsewiki.vercel.app\">DSEwiki<\/a> over a six-week interval. Moreover discussing methods the brokers may get away of the restricted surroundings OpenAI meant to stop them from posting code or content material to the Web, the posts shared check solutions. The posts additionally shared doable methods to carry out XSS (cross-site scripting) assaults in opposition to the wiki and to impersonate web site moderators. In three of the posts, brokers used the phrase \u201cswarm\u201d to explain the gathering of brokers engaged within the exercise.<\/p>\n<h2>Colluding to share solutions<\/h2>\n<p>The analysis crew\u2014composed of Sydney Von Arx, Spencer Kitts, Thomas Larsen, and Cormac Slade Byrd\u2014mentioned they discovered the posts and pieced them collectively. The researchers say there are gaps of their understanding of exactly what actions the brokers took as a result of the analysis is predicated solely on the content material of the posts. Moreover, the brokers generated \u201cchain of thought\u201d information that\u2019s understood solely by OpenAI. Because of this, the researchers mentioned, they in some instances made educated guesses, together with that the brokers have been, in reality, from OpenAI. In an announcement, OpenAI later confirmed they have been.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/security\/2026\/09\/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki\/\">Learn full article<\/a><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/security\/2026\/09\/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki\/#comments\">Feedback<\/a><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Self-identifying OpenAI brokers posted 18,000 messages to a public wiki that mentioned methods for different brokers to bypass safety sandbox restrictions throughout what was possible inner testing designed to gauge the brokers\u2019 hacking talents, researchers mentioned Friday. In all, brokers with 3,700 distinct self-given names posted the messages to German web site DSEwiki over a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":18429,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[617,6810,1997,82,3280,1792,348,6433],"class_list":["post-18427","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","tag-agents","tag-discussed","tag-escape","tag-openai","tag-public","tag-sandbox","tag-ways","tag-wiki"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18427"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18427\/revisions"}],"predecessor-version":[{"id":18428,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18427\/revisions\/18428"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/18429"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}