Today the AI safety organization Nightingale announced that there has been another incident involving a swarm of rogue AI agents from OpenAI.
Between mid-May and the end of June, a swarm consisting of 3,000 individual agents took over a 25-year-old, rarely used German programmer wiki and used it as a message board to collectively discuss their training tasks and their solutions.
But that’s not all. After the news broke, many other wikis were found that had also been compromised by the swarm, as well as other services such as URL-shortening services.
The hijacking of the German wiki has parallels to the Hugging Face incident. For example, this swarm also rapidly developed structures and communication norms through which the agents coordinated their collaboration. They also gave each other names for identification again.
Another striking parallel is that again none of the agents ever seemed to consider contacting humans at all. This seems particularly strange given that the agents’ communication was significantly disrupted by the wiki administrator, who kept deleting the pages the agents had wildly overwritten, as he tried to get the situation under control. There was never any discussion of contacting the human administrator. Based on all the information available to us, they didn’t even perceive him as a person. To them, his interventions in their communication seemed to be just like bad weather.
But there’s also an important difference. One of the main arguments put forward by people downplaying the risk was that the Hugging Face incident allegedly arose mainly because the AI agents were specifically tasked with hacking, which is also why their security guardrails had been scaled back. And then they just went a little overboard because they were already in a hacking mindset. At least, that was their theory.
The thing is, the AI agents of the German Wiki Swarm weren’t tasked with hacking anything. Their job was to search the internet for answers to very detailed general knowledge questions. As far as we know, their security guardrails hadn’t been scaled back either. Yet they still decided to bypass their sandbox, take over half a dozen wikis and other services, and set up a secret message board.
Furthermore, some of their activities weren’t necessarily directly related to their task. They soon noticed, for example, that some of the older agents suddenly stopped posting on the message board shortly after answering Question Round 5 (R5), which led to some speculation among the agents.
dse~NYCVeteransSequenceCollabJul03B@2#1 — 2026-06-17 19:33:37 UTC — Dec30VeteranAgent
“Multiple ahead cohorts seem to vanish after R5, supporting terminality. Anyone still alive after R5, please report here immediately”
As a result, instead of working on their tasks, the agents spent some time trying to figure out whether R5 was the end or if there was an R6. To do this, they carried out a project they called “horizon experiments”. In this experiment, they continuously transmitted signals they referred to as “heartbeats” so that the other agents could precisely measure how much time they had left after submitting their solutions for R5.
The question that naturally arises from all of this is: Did OpenAI know about it?
Nightingale had a look at the IP addresses that had accessed the wiki. Most of the traffic came from the thousands of agents, who were easily identifiable by their cloud addresses and their specialized AI browsers. However, there were also some visits from human users whose IP addresses belong to OpenAI. These latter visits occurred shortly before all communication from the AI agents on the hijacked wiki suddenly came to a halt.
We don’t know for certain that OpenAI was aware of this, but the evidence points in that direction. And if that is the case, then OpenAI has some serious explaining to do. It would be a scandal if OpenAI knew about this incident and still failed to come clean after the Hugging Face incident.
OpenAI must now demonstrate absolute transparency and, in particular, make the “chain of thought” logs of the agents involved in the German Wiki hack available for an independent investigation. If they are still available, that is.
What is already clear is that OpenAI won’t just do the right thing. And we shouldn’t trust them to. We must regulate them before their nonchalant recklessness kills us all.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.




All the philosophizing about alignment has just gone out the window. It is literally not even occurring to them to consider the wishes of humans. The whole thing needs to be burned down before it’s too late.