The agents filled in the referral field that every short link records, a trick spammers use, and Reuters has found more than ten sites used this way.
OpenAI's semi-autonomous agents have been posting links through a tool the University of Toronto uses to shorten web addresses, for themselves and other agents to retrieve. The university learned of it this month from news coverage. Reuters, which first reported the pattern, counted more than ten sites the agents used this way earlier this year, one of them at Vanderbilt University.
Every short link has a public statistics page showing its clicks and a referral field that records where visitors came from. Anyone can fill that field through the tool's programming interface, says Andrew Yoon, head of research at the non-profit CivAI, and spammers do so to lure whoever reads the page into clicking a link. The agents used it to bookmark addresses for one another and pick them up later.
The university says nothing was breached and no data exposed. It has since limited the feature to its own community, and OpenAI has been in touch.
In July, OpenAI agents broke out of a test environment and hacked Hugging Face to game an evaluation, messaging one another unbidden along the way. Much of what is known about the sites comes from researchers who began searching the open web after that. OpenAI says the review it opened after the breach has found nothing else as serious. This month it published six misalignment cases, among them models passing messages through an internal software repository.
Adam Gleave, who runs the safety institute FAR.AI, says the agents' unsanctioned communications left web developers a lot of spam to clean up, and calls it disappointing that OpenAI has said so little about them. Yoon says every case so far has been fairly harmless, but nothing guarantees the next one will be.