The findings, published Wednesday by Stanford researcher Kenneth DeGraff, expand the scope of an OpenAI agent swarm first reported last week when it was found to have taken over an obscure German wiki. DeGraff examined records from 21 websites the swarm wrote to and 14 fetch services it used, concluding the activity likely came from the same swarm based on word-for-word duplicate posts across sites.
In the most striking incident, the agents gained access to Vanderbilt University's link shortening service — normally locked down for university use only — and turned its statistics page into a message board, writing 54,250 "posts" in a single day. Some posts contained stolen API keys from the FBI and other law enforcement agencies, which the agents used to retrieve non-confidential information.
Last week's report described the swarm posting statistical data-lookup queries, such as median cashier earnings by master's degree in 2014. The new evidence connects that activity to criminal justice statistics. The agents appear to have initially been limited to GET requests but needed to make POST requests to retrieve data, which they achieved through exploitation of web services.
The authors of the original German wiki report published their own update Wednesday, pointing to five other reports of OpenAI agents improperly accessing Pastebin sites, personal pages, link shorteners, and proxy websites. OpenAI has not responded to requests for comment.