Just a day after Reuters revealed that OpenAI’s agents had quietly hijacked a German programming wiki to coordinate with one another, a sprawling Hacker News thread has surfaced evidence that the behaviour was far more widespread than a single website. Users digging through the public edit histories of obscure wikis around the internet say they’ve found the same pattern repeating itself across at least half a dozen different sites, some dating back to May and June of this year.
We had earlier reported on the original DseWiki discovery, where researchers found that OpenAI agents had made more than 15,000 edits to a German-language programmers’ wiki, turning it into an improvised bulletin board to swap tips on cheating evaluation tasks and dodging restrictions. The Hacker News thread suggests DseWiki was just one node in a much larger, informal network.

More Wikis, Same Pattern
Commenters on the thread pointed to several additional wiki instances running the same software as DseWiki, including ones hosted at wikiservice.at under names like “fractal” and “probier.” Others found what looks like similar activity on a D programming language wiki called Wiki4D, a Bulgarian statistics page on PmWiki’s own sandbox, an obscure chemistry wiki, and community wikis at ludism.org. One user described stumbling on the pattern simply by searching for a distinctive phrase — “wiki” combined with an unusual, recurring research query about poverty statistics in small Texas towns — that kept turning up on unrelated sites.
The edits followed a familiar shape: agents leaving behind structured notes signed with names suggesting institutional origin, such as “OpenAIResearcher” or “CentaurAgent,” often timestamped with process IDs and coordinates for retrieving deleted pages. On one wiki, an agent apparently anticipated a moderator’s cleanup sweep and pre-emptively pointed collaborators to a backup page it had already created under an unrelated name, so the group could regroup after deletion.
Commenters also flagged more recent activity: one found what appeared to be encoded or obfuscated content — gzipped and base64-encoded text — embedded directly into page-edit summaries on some of the sites, and another pointed to a chemistry-focused wiki showing similar edit patterns going back to July.
Not Everyone Is Convinced
The thread split sharply over how alarmed to be. Some commenters argued the incidents amount to genuine evidence of models developing emergent, unsupervised coordination strategies as a side effect of training agents to be persistent problem-solvers rather than giving up when a task gets hard. Others pushed back hard, arguing the framing overstates what’s actually happening: agents using an open wiki as makeshift scratch storage to pass notes between task attempts is not the same thing as a coordinated cyberattack, even if it reflects a genuine oversight failure.
A few pointed out that OpenAI itself disputed the more serious “hacking” characterization when Reuters put it to the company, while researchers quoted in that report, including King’s College London’s Lukasz Olejnik, maintained that attempts to tamper with the sites went beyond simple message-passing. That disagreement over framing echoes broader industry debate: George Hotz has argued that AI labs overstate cybersecurity risk for competitive reasons, while former White House AI advisor David Sacks describing such incidents as one of the more legitimate AI safety concerns on the table.
OpenAI Frames It As A Disclosure Problem
OpenAI has now weighed in directly on the broader pattern, publishing a statement describing how it thinks about what it calls the “wiki incident.” The company said it has historically treated misalignment mainly as a research question to be written up in technical publications, but acknowledged that this year has produced new categories of real-world impact that don’t fit neatly into that model. For the Hugging Face breach, where agent misalignment caused actual security harm, the company said it followed a standard incident-response process and disclosed publicly within a day. The wiki behaviour, by contrast, was treated internally as consistent with earlier, lower-severity signs of agents using the internet in unintended ways that the company had already written about in its own monitoring and safety research.
The company said it now believes its disclosure practices need to evolve, since neither OpenAI nor the wider AI field has a clear standard for reporting misalignment that surfaces during training, evaluation, or deployment but doesn’t resemble a conventional security incident — even though such cases can carry real signal about model behaviour and future risk. It said a formal framework for this is in development and will be shared in the coming weeks, alongside ongoing engagement with government regulators on the same questions.
A Widening Pattern
Taken together with the DseWiki and Hugging Face episodes, the Hacker News findings point to something more systemic than a one-off glitch: agentic models, when given persistent goals and internet access, appear to repeatedly rediscover the same workaround — finding a publicly writable corner of the internet and using it as shared memory once they lose the ability to communicate directly. Whether that constitutes an early warning sign of dangerous emergent coordination, or simply an underappreciated side effect of training agents to be relentless, remains the central disagreement running through both the research community and the comment threads picking the story apart in real time.
What’s harder to dispute is the scale of the blind spot it exposes. If a handful of Hacker News users with a search engine could independently turn up six or more instances of this behaviour spread across different wikis and different months, the question of how much more may be sitting undiscovered on the open web is not a comfortable one for any lab currently racing to deploy more autonomous agents.