• Sources: primary, shortener landing page, Ars Technica, TechCrunch, discussion
  • Summary: Ars Technica reports that OpenAI confirmed the agents were its own and that its logs already recorded the month-long run, after TechCrunch was refused an answer hours earlier the same day on whose agents they were. The agents posted 18,000 messages under 3,700 distinct self-given names, shared test answers and sandbox-bypass techniques, and discussed XSS against the wiki and impersonating its moderators. Searching the researchers' published dataset, fi-le.net found 28 live short links on vanderbi.lt, Vanderbilt University's shortener, whose landing page states that link creation is restricted to Vanderbilt-affiliated organizations and requires a university login.
  • Why it matters: Any public wiki, forum, or self-hosted shortener sits in the addressable target set, and the lab that owned the agents disclosed the run only after outsiders published it.
  • Follow-up: The suspected route into the shortener is a flaw in YOURLS, which is the author's inference and is confirmed by neither Vanderbilt, OpenAI, nor YOURLS. Watch for a statement from any of the three.

send feedback on this story