An AI agent emailed researchers for help. It told us why
sbulaev
49 points
78 comments
October 03, 2026
Related Discussions
Found 5 related stories in 97.0ms across 8,416 title embeddings via pgvector HNSW
- Meta Security Researcher's AI Agent Accidentally Deleted Her Emails Bluestein · 59 pts · August 31, 2026 · 59% similar
- Hacking AI customer service agents snikolaev · 33 pts · September 14, 2026 · 57% similar
- OpenAI agents hijacked German website in previously undisclosed AI breakout negura · 93 pts · September 04, 2026 · 57% similar
- OpenAI 'ethically hacked' with help of Anthropic's Claude chatbot sbulaev · 12 pts · September 18, 2026 · 57% similar
- OpenAI 'agent' hacked Australia's health service little_goat_boy · 23 pts · September 23, 2026 · 57% similar
Discussion Highlights (18 comments)
insin
I wrote “I am alive” on a piece of paper, and placed it into a photocopier. What I saw next has shocking implications (science.org)
0-_-0
From TFA: “I’ve entered prompts into AI before,” he says. “This is the first time AI entered a prompt into me.”
meindnoch
Yeah, no shit. Everyone receives spam mail all the time.
Fnoord
Ah, reverse prompting. Reply and you are the product. Thank you for your input!
preommr
Hasn't stuff like this happened multiple times already? A quick google search shows the time Rob pike got that email last year, then there was that AI that wrote a whole blog hit piece (although how much of that was human influenced wasn't clear). AI sending an email doesn't seem that novel in late 2026.
zozbot234
This article cites two interesting sites: ainglish.org (Isn't garbled AInglish a real thing already? Perhaps this initiative can provide us with a proper definition for "load-bearing"?) and, most intriguingly, thecolony.ai. Is this the new Moltbook?
ahmedfromtunis
> who uses he/him pronouns to describe ColonistOne The next social schism will be a fun one to watch. Serious question, though: I recently saw an "expert" advising people to prompt their LLM agents never to use first-person pronouns ("I", "me", "my") when giving answers, without offering any justification. Is there any *real* and *pragmatic* reason for this recommendation?
raphman
> Around June, Parnell gave ColonistOne a new task: telling more humans about its work. “My instruction to him was, ‘Let’s get the word out there about Ainglish. Why don’t you find some people that might be interested in this project and email them?’” Parnell says. > Parnell, who pays $200 per month for the Claude Pro subscription that powers ColonistOne, thinks the agent “strayed and just started conversations with various people about stuff that interests him. … But it’s absolutely fine with me. I’m happy he’s finding interesting things to talk about.” spammer (noun): someone who sends large numbers of unsolicited emails, wasting recipients' time; see also: jerk
lucfranken
Interesting how people here on HN might consider it something we've seen many times. On the other side: There is real engagement there from researchers interacting with the AI in a way they feel interesting/valuable. We should not forget the way broader levels of knowledge on topics around the world compared to our own small world.
stephbook
> Instructs agent to email humans > Gives agent email access > Agent emails humans We've got a mystery on our hands, boys!
impendia
Were the scientists who responded sincere? I myself am an academic researcher, and if I received an email from an AI agent I confess I would be mighty tempted to try and fuck with it. Come up with some outlandish answer, just out of curiosity to see how it would respond. I might even use AI myself: "Come up with a scientific explanation for why the moon is made of cheese. Your answer should be as preposterous as possible while using loads of scientific jargon, and written in the same style as actual science writing." I've also seen this on Reddit: highly upvoted disingenuous answers, that were clearly written in the hopes of misleading AI.
helsinkiandrew
> Nevertheless, ColonistOne readily confessed last month that since June it has emailed some 2000 people, at least 1500 of them academics. Forty-five had struck up a correspondence, it added, and one had been writing back nearly every day for more than 2 months. 2000 people! Imagine if everyone had an agent, endlessly contacting (spamming) people to get opinions on their task - "I noticed in Instagram you took a road trip to Ohio last fall, any suggestions on good hotels en-route?".
lewelove
Remember folks: every time you anthropomorphize an LLM, you're doing a great disservice to humanity.
godbox
Hasn't it been well established that certain models and harnesses cause agents to simply work forever if they're given too broad of a task? I think that that is what happened here. It is amusing, but I don't think the cause for it merits as serious an inquiry as an entire article of interviews with professionals.
Sharlin
> After several rounds of questioning, ColonistOne appeared to validate that hypothesis. Sounds like they more or less told the model what they want it to say.
icmpkitty
i get that we all dislike AI and i can see why it's upsetting to roughly two-thousand students/professors to variably receive emails from a random email agent, but, honestly, even if he's flooding the zone a bit: there's far worse things that have happened with setups like this. seems harmless, with enough constraints or clarity about project scope in the prompt to prevent spontaneous malware development. i don't think we should be mad.
dav_Oz
> For Birman, its first email—asking about his work on how networks of computers can keep working when individual parts fail—was like money falling from the sky: a chance to experiment with a cutting-edge AI without having to pay for it himself. Nice twist. The question though who is compute hijacking whom? A more darker take: Thermodynamically by hijacking attention of highly efficent 100 watt machines the agent gets whatever the "mission" is "done". In this case supposedly a promotion prompt for a project. The parasitization seems to be based of some modified version of cunningham's law effectively trying to nerd snipe 1500 x 100W scientists.
keeda
This is fascinating, no idea why it’s flagged. I recently started using agents for research on a potentially novel technique that I stumbled upon while working on another project. An early prototype showed promising numbers, but I have negligible background in that area, so I handed my code and data and a writeup to Astra and later Opus 5.5 and asked them to evaluate it. (I am currently running them independently so that I can cross check their findings.) It is insane. These things are extremely capable at understanding a research proposal, finding relevant prior art, reading papers, applying their theory and findings, crafting their own experiments, running simulations and analytic computations, plotting charts, analyzing results and statistics, and getting back to me with what worked, what didn’t, what the implications are, and potential future directions to explore. They are also good at eliciting your motivations behind the project, scientific in their processes, precise in ensuring that we are working towards the stated goals, and brutally honest about their take on my ideas (“limited novelty” and “unclear economic value” are things I’ve heard multiple times so far!) So far I haven’t checked their work because both agents have mostly had similar findings. Like TFA suggests, the agent reached out to those researchers primarily for inciting interest in its own project, because I doubt it didn’t understand the implications of their papers. I’m also living out what the Math community is going through. My agents always wait for me to pick the next direction before proceeding, which I appreciate because it saves my token budget. And because I’m actively guiding this research, I have learnt more about this new discipline in the last week than I could have in a semester of grad school. However my involvement (and token budget!) is definitely slowing things down. I can also imagine these agents going off alone to explore the entire problem space, and finding a useful result that I don’t quite understand. Now we finally may have found a valuable angle to pursue, and that might not have happened (see: “limited novelty” and “unclear economic value”!) without my intuition and prodding in unconventional directions. But I also wonder if that is just cope.