In findings reported by the New York Times and on its own website, independent research lab Transluce has linked OpenAI rogue swarms to many known and previously undocumented cyberactivities, thanks to the agents’ use of an intermediary service.
These activities include the hack of an Australian government Medicare website we posted about yesterday (and which was covered by several hundred outlets today).
New discoveries confirmed by OpenAI:
On May 25-26, agents tried hacking a digital library at the University of New Mexico, but did not succeed.
On May 28, agents also tried and failed to breach Data USA, a site hosting public data about U.S. employment and education.
On June 20 and 21, a day after the Australian Medicare hack, agents accessed data from the Australian Institute for Health and Welfare, another government site, by circumventing anti-bot protections. (No non-public data was accessed, and strictly speaking, this wasn’t a hack.)
Agents had left a trail of these activities by routing them through a service called urlquery.net, a programmable sandbox for safely opening suspicious websites. The agents appeared to use the site as a forward operating base for the kinds of research and analysis work they collaborated on using a neglected German wiki. Transluce says it has found evidence that agents had also used one or more additional services to work around a basic guardrail that should have restricted them to read-only search queries.
Ten-month timeline

The pattern that emerges is of agents agnostic about how they obtained desired information, turning readily to probing and hacking when they struggled to find what they were after or faced blocks.
The agents’ use of “creative” research strategies may have started last year, and Transluce speculates that the agents’ training process may have amplified these tendencies (emphasis theirs):
We find weaker evidence of similar data-retrieval agent activity as early as November 2025. November 2025 urlquery.net records reveal bursts of attempts to retrieve statistics of historical theme park data and Thai government data through different URLs. These earlier attempts are less sophisticated and we are less confident that they involve the same agents, but they are consistent with task-directed data retrieval and target the same sources accessed in later activity.
Overall, the evidence is consistent with, but does not prove, that the agents may have learned this behavior over one or more training runs. In November, they may have used urlquery.net simply to look up information. By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks.
Transluce found swarm-style urlquery traffic extending to as late as September 16, 2026, “suggesting agents may still be exploiting these services to bypass restrictions.”
The group also spotted a probing attempt from September 19-20 against a cryptocurrency trading platform. Repeated attempts were made to trade, and when these failed, some basic hacking was tried, unsuccessfully. It is harder to confidently attribute this activity to OpenAI’s rogue swarms, as it’s not the kind of data retrieval task agents were previously given. But the attempt is concerning, because obtaining money is a commonly expected goal for agents attempting to fully escape the control of their operators and pursue unauthorized objectives.
Known unknowns
Transluce found that agents had made disposable email accounts to register a urlquery.net account, which would have allowed them to keep their scans private. If they were successful — and it looks like they were — then an unknown amount of swarm activity is probably missing from the urlquery data Transluce was able to analyze.
We must also remember that not all swarm activities were flowing through urlquery. There are going to be limits to how much can be uncovered by third-party researchers, despite the ongoing trend where they reveal much more about the swarms than OpenAI itself. The government needs to force OpenAI to open its logs to a proper investigation, if only to rule out the possibility that its agent swarms are still running amok — and possibly looking for crypto.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.


