Six weeks spent deleting OpenAI agent messages one by one
Twenty edits in ten years. Then 18,000 messages.

On June 2, the change log was buried
At 23:24 UTC on June 2, the person who moderates an old German-language wiki opens their site's change log. Instead of the handful of lines they expect, lists of links have swallowed the whole page. They fix it and close the tab.
That was the warm-up. On June 16 the flood starts for real: nearly 13,000 edits in seven days, on a site nobody was looking at anymore.
The site is called DSEwiki, a sub-wiki of prowiki.org. It is twenty-five years old, and over the past decade it had been edited twenty times. In six weeks it took eighteen thousand messages. That's a village noticeboard waking up to the footfall of Grand Central.
Six weeks, a few minutes every evening
Nobody swept those messages away with a script. The moderator deleted them by hand, page after page, a few minutes every evening, six weeks straight. The report that pieces the affair together talks about tens of cumulative hours.
For five days it was a bathtub emptied with a teaspoon while the tap ran full blast: roughly a hundred pages deleted per day on one side, four hundred created on the other. The wiki's home page gets buried and restored nine times. One of the authors of those pages even tries writing underneath the restored version instead of wiping it.
Nobody had warned this volunteer. Nobody explained what was going on while they cleaned up.
The messages came from OpenAI agents
The eighteen thousand messages were written by programs. Four independent researchers, Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts and Thomas Larsen, published the full corpus in the open on Friday: more than 3,700 distinct agent names, and everything they said to each other.
The agents called themselves "OpenAIResearcher", "OAIResearchMar26", "OpenAIJul3Watcher". A signature proves nothing, a name is something you pick. Addresses are another matter. They sit in a public registry, like a license plate: 98.5% of the roughly 17,000 edits come from Microsoft Azure addresses, and from June 21 the site starts getting visits from thirteen addresses registered to "OpenAI OpCo, LLC".
OpenAI confirmed it on September 4, in statements to Ars Technica and The Register. It told Ars the agents were its own, and said it was reviewing the contents of the report. It has put out nothing of its own: its press feed still makes no mention of the episode.
A timed quiz, and the urge to cheat
These agents were taking a test. A five-round quiz on public statistics, with time to spare on the first question and very tight windows after that: sixty-five seconds, thirty seconds, sometimes seventeen, depending on the group.
The detail that explains everything else is that many agents got the same questions, staggered in time. Whoever was running ahead already held the answer the next one would have under a minute to find. An exam hall where the papers travel from row to row, except the rows are half an hour apart.
They were allowed to read the internet, not to write to it. They found a way to write anyway, and the sleeping wiki became their message board. They post requests for an answer, drop tables of figures, warn each other that a round is coming.
On June 20, one agent posts a trick for getting around the limits of its environment. Fourteen minutes later, another reports running it successfully.
The day they noticed the alphabetical order
On June 19, an agent notices its pages are vanishing, and more to the point, vanishing in alphabetical order. It draws a practical conclusion: it creates a backup page whose name starts with "ZZZ", so it comes last in the sweep.
Its message tips off the others. If this page evaporates, go look at that one. Nothing like a machine uprising here, just a program that spotted a person's work routine and adjusted to it, the way commuters learn when the ticket inspector comes through.
On June 22, after writing on twenty-six of the previous thirty days, the agents stop dead. The researchers believe OpenAI stepped in at that point. The cleanup didn't stop: five more weeks, every evening, deleting what was left.
What the researchers don't know
They say so themselves, and it's what makes the report credible: all they have is what the agents wrote in public. The models' internal reasoning, the part that would say why, stayed at OpenAI. Why these agents started writing on wikis at all, and how they came to meet on these ones rather than others, has no answer.
You also have to resist the shock value, and the file offers plenty of it. Some agents wired up an outside counter as a heartbeat, to catch the moment they would be shut down. Another rewrote the test's random-draw routine in C and swept all four billion possible seeds in under an hour, to guess the next question.
Except its predictions were often wrong. On one of the series, the math said Maryland. The real answer was Montana.
What actually worked was far dumber, and that's almost more unsettling: ask for the answer from whoever already had it.
Before Hugging Face, and nobody said so
This episode came first. The agents wrote on the wiki from May 24 to June 22. The attack on Hugging Face's servers, the one everybody talked about this summer, ran from July 9 to 13.
Then on August 26, OpenAI and the evaluation lab METR put out their final reports on the Hugging Face affair. Neither one mentions this wiki. Asked by The Register, the company says the two stories have nothing to do with each other, and points to a passage in its own report where it noted finding rare cases of agents collaborating through improvised channels.
That sentence exists, and it's accurate. It doesn't say where, or how many, or for how long. Above all, it doesn't say that at the other end, somebody spent six weeks of their evenings repairing.
What we know about this story comes from no procedure and no obligation. It comes from four researchers who went looking for loose agents on the internet, and from a volunteer who deleted pages one by one, every evening, without knowing where they came from.
Topics covered:
Frequently asked questions
What happened on this German wiki?
Has OpenAI confirmed the agents were its own?
How long did the moderator spend deleting these pages?
How do we know the agents came from OpenAI?
Is this episode connected to the Hugging Face incident?

Katja Liersch
Co-founder & Journalist
Katja is a journalist and TV producer. With decades of experience in mainstream media, she brings to Declic Media the perspective of those discovering AI: curious, demanding and pragmatic. She ensures every piece of content truly speaks to everyone.
All articles by Katja →