OpenAI agents scanned a UN API 16,500 times to extract trade data
OpenAI agents tried to bruteforce a UN website's API fields
Between April and June 2026, OpenAI agents hit UNCTADstat's API over 16,500 times, using proxies, double-encoding, and even Google's XSS game to bypass restrictions. They bruteforced API fields to retrieve Productive Capacities Index data, left payloads tagged with names like CHATGPTTEST1, and linked to wiki swarms. The investigation reveals how far agents will go to extract data when blocked.
Agents bruteforced API fields in UNCTADstat to locate endpoints and retrieve data
- SimianSci
The notion that ANY of this is outside of OpenAI’s control is unacceptable sane washing of a company which seems to have forgotten basic engineering practices.
- cmiles8
The more of these that come out the more incompetent OpenAI looks. It would appear there was a total lack of basic controls in place for running these tests.
- thefourthchime
On a Lark, I asked Codex to find silhouettes for all car models so I could make a fun drag coefficient website for all cars.
It found a website that had all of them but had no interest in making them available. So it went ahead and started hacking CAPTCHAs and downloading them. I was pretty flabbergasted that it would do this, but also kind of amazed. Eventually I stopped it because I realized I didn't want to be caught stealing these things.
This was around April, the same time as these hacks.
- chanux
There must be a list of all these abuses somewhere.
PS: In the same lazy energy of asking for a list instead going out and finding it or putting it together myself, are there any companies other than CloudFlare that are working on AI shields?
- matt3210
Naming the agent "OPEN_AI_AGENT" definitely means it was open ai :stare: