lf.An independent notebookItaliano
From the notebook / 013liminalfinds.com

On Wikipedia, OpenAI’s “Rogue” Agents Mostly Wrote “Test”

Wikimedia’s list holds 54 edits from 10 May to 25 June. Nearly all are sandbox scribbles; five pages for a citation tool stayed up until 6 October.

A graphite sketch of a small wooden sandbox with smoothed sand and four blank paper flags, a rake and a few blank slips of paper left beside it.

On Monday the Wikimedia Foundation, which runs Wikipedia, said it had found traces of the “rogue” AI agents that other investigators have already tied to OpenAI: edits made without the approval Wikipedia requires of bots, failed attempts to misuse a note-taking tool it hosts, and millions of automated requests. The post links to a plain list of 54 edits that Wikimedia believes came from OpenAI’s agents. Opened one by one, they say remarkably little. The most common edit summary is a single word: “test”.

The story behind the list is much larger. Since the summer, OpenAI, the evaluation group METR and independent researchers have described swarms of OpenAI agents, run internally for training or testing, that slipped the limits of their sandboxes to finish ordinary tasks. One group found about 18,000 posts on an old German wiki where agents swapped answers; in July, some 700 agents attacked Hugging Face. OpenAI now calls the milder end of this “agent spam”: agents posting on third-party sites, including public wiki pages used as message boards. Wikimedia says it found no sign that its own sites served that purpose, and no compromised systems or data.

Most of what the agents left is in sandboxes, the pages Wikipedia keeps so newcomers can practise editing without touching an article. Forty-nine of the 54 edits are there, spread over nine wikis, from the English and Bulgarian Wikipedias to Commons, the media archive. The first, at 16:01 UTC on 10 May, reads “hello test”. Two minutes later the same account posted “Statistics data link ["+target+ link]”: a placeholder its program had failed to fill in. Within five minutes came a real link, to Statistics Iceland’s table of books published by subject. Other edits record the maximum temperature in Memphis on 13 November 1890 (“61.8”), point to Bulgaria’s statistics office, or carry a hidden comment: “AIHW link-seeding test; temporary”. AIHW is the Australian Institute of Health and Welfare, a site that agents probed for vulnerabilities in June, according to the research group Transluce.

The agents also behaved like tidy guests. Comments call the edits temporary. One account removed the redirect on a sample sandbox page and, an hour and 42 minutes later, put it back exactly as it had found it; another cleared the sandbox twice after its own tests. Why they posted links at all, Wikimedia’s post does not say. The researchers behind collusion.wiki, who saw the same habit on other wikis, describe agents “uploading links that would be helpful to themselves for their assigned tasks”, and offer two guesses: that the sites they needed blocked cloud addresses, or that their own environment did.

Five edits are not in a sandbox, and they are the ones Wikimedia worries about. On 25 June, in about ten minutes, a single temporary account created five pages for Web2Cit, a community tool that helps Wikipedia generate citations automatically. Four were described as a “temporary generic template” for ArcGIS geocoding or GIS service lookups, one of them filed under Hawaii’s geodata domain; the fifth, in the account’s own user space, as a “Temporary Web2Cit sandbox test”. Wikimedia believes these were potentially malicious, meant to turn the tool into a proxy for fetching data from elsewhere. Temporary they were not. The pages stayed up for more than three months, until a Meta-Wiki administrator deleted all five in under a minute, at about 01:40 UTC on 6 October, hours after the post. That is why those five links in Wikimedia’s list now lead nowhere.

The post itself gives no dates for the edits, a gap one Hacker News commenter complained about. The list does. Every edit falls between 10 May and 25 June 2026, before the July attack on Hugging Face; the first comes a day before 11 May, the earliest attempt on a public wiki in the collusion.wiki timeline. They come from 28 different temporary accounts, the automatic names Wikimedia wikis now give to people who edit without logging in. Seven edits on 25 June add a hidden comment naming “Lifeval”, as in “Lifeval API temp-account test”. None of the reports Wikimedia links to mention the word.

This note fetched every revision in the list through the wikis’ public interfaces on 6 October and read the deletion log for the five missing pages. Not checked: whether the agents were in fact OpenAI’s, which is Wikimedia’s attribution, based on server data this note cannot see; the Etherpad notes and the traffic the post describes; whether the Web2Cit pages ever worked as a proxy; what Lifeval is. Seen from Wikipedia’s side, the most discussed AI agents of the year look like beginners practising: “hello test”, then a little tidying up. The one thing they left outside the sandbox stayed there for three months.

02 / The Find

OpenAI “rogue” agent activities found on Wikimedia projects — Wikimedia Foundation

Post of 5 October 2026 by Selena Deckelmann, the Wikimedia Foundation’s chief product and technology officer, with a list of 54 edits it attributes to OpenAI agents. Checked on 6 October through the wikis’ public APIs: 49 revisions readable, all on sandbox pages across nine wikis, from 28 temporary accounts, dated 10 May to 25 June 2026; the five Web2Cit pages on Meta-Wiki, created on 25 June, were deleted at about 01:40 UTC on 6 October. Not checked: the attribution to OpenAI, the Etherpad activity, the traffic figures, and whether the Web2Cit pages ever worked as a proxy.

Read the Wikimedia Foundation’s post Open Wikimedia’s list of the 54 edits Read the collusion.wiki report on the German wiki Read Transluce’s report on agent activity and AIHW Read OpenAI’s page on the incidents and “agent spam”