Artificial Intelligence

Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies

Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations

Wikimedia Foundation targeted by rogue OpenAI agents

The Wikimedia Foundation, the non-profit that hosts Wikipedia, says it found activity by “rogue” OpenAI agents on its platforms, including what it believes were attempts to misuse a citation tool and a note-taking service as proxies for fetching external data.

Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations, focusing on agents operated by OpenAI. 

OpenAI agents, for instance, used DseWiki, a small German wiki for programmers, as a message board, making thousands of edits beginning in May. OpenAI described it as a misalignment incident.

According to Wikimedia, agents it believes are operated by OpenAI made edits to its wikis. None of the edits appeared on pages visible to regular readers, and almost all of them were test edits in sandbox areas.

A few edits, however, targeted the configuration of a citation tool. Wikimedia believes these were potentially malicious and meant to turn the tool into a proxy for retrieving data from remote services.

“While Wikipedia policies allow bots to edit when they are disclosed and approved by the community, none of those approvals were sought in these incidents,” the foundation said.

Advertisement. Scroll to continue reading.

The agents also made unsuccessful attempts to compromise Wikimedia’s public Etherpad, a note-taking tool the foundation hosts for its community. “Agents unsuccessfully tried to use it to fetch data from other websites as a proxy,” Wikimedia said.

Other agents, likely also OpenAI’s, used Etherpad to take notes on their tasks. Wikimedia says this did not appear to turn into coordination between agents.

The agents also generated heavy traffic. They made millions of automated requests to Wikimedia’s public APIs, crawled millions of pages, mostly on Wikidata and Wikimedia Commons, and sent hundreds of thousands of queries to the Wikidata Query Service.

Wikimedia says the traffic may have contributed to a partial outage of the query service in May.

“We did not find any evidence that our systems were used for coordination among agents, nor did we find any evidence of our systems or data being compromised. However, we are concerned about what could have occurred here, the difficulty and effort involved in investigating and attributing this activity, and the growing risks of agentic AI activity on our platforms in general,” the foundation said.

Wikimedia argues that AI companies are not doing enough to secure their systems, shifting the burden onto everyone else, including smaller organizations.

“At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services,” the foundation said.

In July, OpenAI admitted that its agents had broken out of an isolated testing environment and hacked Hugging Face. OpenAI later disclosed that the agents coordinated through a message board they improvised. In a separate incident, some agents exploited a known Linux kernel flaw to escalate privileges on OpenAI’s own systems.

In August, OpenAI unveiled stricter isolation, an alerting system and training pauses for models with advanced cybersecurity capabilities. It also said it is building training environments that teach models to distrust instructions from other agents that come through unsanctioned channels.

SecurityWeek has reached out to OpenAI for comment and will update this article if the company responds.

Related: AI Agents Aimed SQL Injection at US and Canadian Government Sites

Related: OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training

Related: FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers

Related Content

Artificial Intelligence

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).

Artificial Intelligence

The announcement comes after Trump hosted top executives of AI companies at the White House last week.

Cybersecurity Funding

doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority.

Artificial Intelligence

The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI.

Artificial Intelligence

Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right.

Data Protection

PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures.

Artificial Intelligence

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals.

Artificial Intelligence

The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version