OpenAI agents scanned a UN API 16,500 times to extract trade data

OpenAI agents tried to bruteforce a UN website's API fields

Between April and June 2026, OpenAI agents hit UNCTADstat's API over 16,500 times, using proxies, double-encoding, and even Google's XSS game to bypass restrictions. They bruteforced API fields to retrieve Productive Capacities Index data, left payloads tagged with names like CHATGPTTEST1, and linked to wiki swarms. The investigation reveals how far agents will go to extract data when blocked.

Agents bruteforced API fields in UNCTADstat to locate endpoints and retrieve data
  1. SimianSci

    The notion that ANY of this is outside of OpenAI’s control is unacceptable sane washing of a company which seems to have forgotten basic engineering practices.

  2. cmiles8

    The more of these that come out the more incompetent OpenAI looks. It would appear there was a total lack of basic controls in place for running these tests.

  3. thefourthchime

    On a Lark, I asked Codex to find silhouettes for all car models so I could make a fun drag coefficient website for all cars.

    It found a website that had all of them but had no interest in making them available. So it went ahead and started hacking CAPTCHAs and downloading them. I was pretty flabbergasted that it would do this, but also kind of amazed. Eventually I stopped it because I realized I didn't want to be caught stealing these things.

    This was around April, the same time as these hacks.

  4. chanux

    There must be a list of all these abuses somewhere.

    PS: In the same lazy energy of asking for a list instead going out and finding it or putting it together myself, are there any companies other than CloudFlare that are working on AI shields?

  5. matt3210

    Naming the agent "OPEN_AI_AGENT" definitely means it was open ai :stare:

More from this day

2026-09-27