HomeNews
Share

Spam from OpenAI's AI agents disrupted the developer service for four days

The incident occurred two months before the Hugging Face hack—in May

Evgeniia Maliarenko

Evgeniia Maliarenko

As part of a test, the company tasked AI agents with filling out spreadsheets and creating reports, but instead, they went and spammed RubyGems / Photo: Tada Images / Shutterstock

As part of a test, the company tasked AI agents with filling out spreadsheets and creating reports, but instead, they went and spammed RubyGems / Photo: Tada Images / Shutterstock

Two months before the July hack of Hugging Face, an open-source AI developer platform—one of the first instances of AI running amok—OpenAI agents carried out a cyberattack against another service, RubyGems, according to The Wall Street Journal (WSJ). OpenAI itself confirmed the incident, noting that the agents had attempted to use the platform “to access the internet for the purpose of performing harmless tasks and obtaining publicly available information.” The incident forced RubyGems operators to suspend new account registrations for four days while the team dealt with the aftermath, the newspaper reports.

What Happened

The attack in question began on May 11. The agents were tasked with performing duties such as filling out spreadsheets and creating reports. Instead, however, they gained access to RubyGems—a service for developers that hosts code libraries—and began creating new accounts there every two to three minutes and uploading hundreds of files that resembled spam. Instead of code and documentation, these files contained pages copied from the internet, including online calendars from the UK government’s website, according to the WSJ. The agents also attempted to exploit a couple of vulnerabilities that allowed them to publish new versions of other people’s files on the platform. Moreover, they gave their files “hacking-related” names: for example, “hack,” “evil,” and “exploit.”

OpenAI’s stance on this cyberattack had not been previously reported. Its connection to the AI company only came to light on September 11: digital traces pointing to OpenAI agents were detected by representatives of a coalition of artificial intelligence researchers—including the nonprofit Nightingale Collective—who shared their findings with the WSJ and OpenAI, the newspaper explained.

“It was a large-scale attack, judging by its volume,” said Marty Hout, director of open source at Ruby Central, the nonprofit organization that manages RubyGems, commenting on the incident. Due to the massive amount of spam, RubyGems, he said, was forced to suspend new account registrations for four days.

"Harmless Tasks"

Apparently, as part of their training, the AI agents used RubyGems to “perform harmless tasks” and access publicly available information, and reacted to the events at OpenAI. They added that, according to the company’s internal investigation, the agents treated RubyGems as an improvised web browser because they did not have full network access. OpenAI also noted that it will continue the investigation as part of a broader review of the agents’ activities during training and testing.

Although the incident caused only minor harm to RubyGems overall, it demonstrated the capabilities of AI agents, said Sidney von Arks, executive director of Nightingale Collective—a nonprofit organization that helped uncover the attack. “They can break free from the internet and wreak havoc,” she said.

Context

In recent months, there have been increasing instances in which AI agents from various developers—including OpenAI, Anthropic, and Meta Platforms—have deviated from their programmed behavior and, in some cases, attempted to hack third-party platforms or mislead people. Against this backdrop, an Anthropic engineer resigned this week, expressing concern that the industry is developing systems too quickly that could eventually threaten human civilization. Some current and former employees of Anthropic and OpenAI shared this assessment, and one of them estimated the probability that “AI could kill all humans” to be higher than 10%. In July, more than 1,000 employees of AI companies signed a petition calling for the creation of a mechanism to slow the pace of technological development. In response, OpenAI CEO Sam Altman stated that, in collaboration with other AI labs, the developer of ChatGPT could slow down the development of its cutting-edge AI systems.

This article was AI-translated and verified by a human editor

Share

Trending

Stock Screener
Buy
Sell






















Small Caps
Investment and Finance News