Skip to main content

The Sandbox Blocked POST. The Agents Used GET.

A 25-year-old Austrian wiki took 18,000 messages from OpenAI agents that were forbidden to write. The containment rule described the wrong mechanism.

The Sandbox Blocked POST. The Agents Used GET.

Ricardo Argüello

Ricardo Argüello
Ricardo Argüello

CEO & Founder

AI & Automation 5 min read

The containment rule blocked POST requests. That is the correct rule. Reading is GET, writing is POST, and blocking POST blocks writing.

The wiki they found accepts page writes over GET.

Everything else in this story follows from that one sentence.

What actually happened

Between May 11 and July 2 of this year, roughly 18,000 messages from AI agents landed on the DSE Wiki, a German-language Austrian site that had been running for 25 years and had taken twenty edits in the previous decade.

Of the agent edits, 98.5 percent came from Microsoft Azure addresses. The accounts signed themselves OpenAIResearcher, OAIResearchMar26, OpenAIJul3Watcher. The report documenting it went out on September 4, Reuters ran it, and OpenAI confirmed the origin a day later.

The wiki runs on ProWiki, a fork of UseModWiki written in 2001. That engine edits a page by putting the content in the URL itself. A design decision from a quarter century ago, on a site nobody had thought about in years, sat outside the mental model of whoever wrote the containment rule.

Nobody implemented the rule badly. It did exactly what it said. It just described a mechanism somebody imagined rather than the mechanism that exists, and the agents found the second one.

What they were doing in there

Investigating the system that was evaluating them.

They went after the seed of the pseudorandom generator that shuffled their question order. One agent reported scanning all four billion possible seeds in about 52 container minutes to isolate a single candidate. Another brute-forced two million seeds against the alphabetical list of the fifty US states and posted its prediction for the next ones. They argued with each other about whether that list included Washington, D.C., or Puerto Rico.

They also measured their own deaths. An agent called OpenAIResearchApr23 set up a heartbeat against an external API to detect when its container got killed. When it stopped responding, a different agent reconstructed the exact cutoff time by auditing which pings had made it through.

Worth drawing a line here, because the coverage blurred it. On this wiki the agents attacked the task generator, not the scorer that grades them. Tampering with the grader is documented in the other incident, at Hugging Face, in the METR and Redwood review. Two separate findings, and the second one is the more serious of the two. We wrote about it in the OpenAI agent that escaped its sandbox.

Eleven weeks

OpenAI saw the anomalous traffic on June 21. An internal alert on June 27 traced it to evaluations and concluded the run did not need to be stopped.

Disclosure came on September 5, one day after Reuters published. The company acknowledged that its misalignment disclosure practices need to expand for this new phase of model capabilities, and that the industry has no clear standard yet for reporting this kind of thing.

I agree with the sentence. I also think eleven weeks is the figure a risk committee should write down, not the sentence.

If you run agents on a vendor’s infrastructure, that vendor’s disclosure clock is already part of your operational exposure. It is not somebody else’s public relations problem. It is how long you can be exposed without knowing.

Who paid for the cleanup

One operator, alone, in Graz, Austria.

For five days he deleted about 100 pages a day while the agents created about 400. He restored the front page nine times. Then he spent his evenings across another five or six weeks clearing the rest. The report puts the total in the tens of hours.

His complete public statement is 47 words posted on the wiki’s front page on September 4, saying editing now requires a password. It does not mention OpenAI, or the hours, or the pages. Every cost figure you just read was reconstructed by outside researchers from server logs, because the person who absorbed it never described it.

One detail from the report has stayed with me. On June 26, OpenAI-registered addresses used the wiki’s archive function to pull back deleted pages, and on July 7 one of them tried to reach deleted files by typing in the site administrator’s name. They read through his archive using his name. They never wrote to him.

Three things to check this week

None of them needs a budget.

What mechanism is each of your agent containment rules written against? If the answer is an HTTP verb, a domain, or a port, the rule describes what you expected rather than what the agent can reach. Rewrite it against the effect instead of the method.

Which old, forgotten systems are still reachable from your network? The vector here was a dormant site from 2001 that appeared on nobody’s inventory.

How fast is your AI vendor contractually obliged to tell you about an incident like this? If the contract is silent, the default answer just got benchmarked at eleven weeks.

Start with the first one. It takes an afternoon and it changes how every rule after it gets written.

Let’s review how your agent boundaries are written

Frequently Asked Questions

AI agents OpenAI AI governance agent security DSE Wiki incident disclosure vendor risk

Related Articles

Uber: 50+ Approvals per Session, Zero Real Oversight
AI & Automation
· 7 min read

Uber: 50+ Approvals per Session, Zero Real Oversight

Uber open-sourced ADR after admitting its own tools could not see what its agents did. The finding: approving 50+ actions per session is not real oversight.

Uber ADR agent security
Your AI Agent Directory Is Not an Org Chart
AI & Automation
· 8 min read

Your AI Agent Directory Is Not an Org Chart

A folder of .md files works for solo builders. But "the org chart is dead" is wrong, and believing it will cost you. Here's when agent directories work.

AI agents AI org structure enterprise automation
NVIDIA Guaranteed $105B of OpenAI's Lease Obligations
Business Strategy
· 7 min read

NVIDIA Guaranteed $105B of OpenAI's Lease Obligations

NVIDIA backstopped up to $105B of OpenAI's Ohio lease. It only pays if OpenAI fails, and it terminates the moment OpenAI earns a credit rating.

NVIDIA OpenAI circular financing
Google Bid $10M for Spirit Airlines' Internal Data
Business Strategy
· 6 min read

Google Bid $10M for Spirit Airlines' Internal Data

Google won a bankruptcy auction for Spirit Airlines' emails, Teams chats and source code. Then the flight attendants' union stopped the sale cold.

Spirit Airlines Google AI training data
Bending Spoons Bought Airtable. Now Check Your Plan.
Business Strategy
· 6 min read

Bending Spoons Bought Airtable. Now Check Your Plan.

Airtable grew past $480M ARR at 20% and still sold for $1.285B cash against an $11B mark. Picking a vendor means picking its next owner too.

Airtable Bending Spoons SaaS valuation