Early rogue AI agent activity and attempts to hack found on urlquery.net

snikolaev 256 points 257 comments September 24, 2026
transluce.org · View on Hacker News

Discussion Highlights (20 comments)

lapkaaaa

blackwall when? XD

alex-moon

It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.

yewenjie

OpenAI agents these summer are like a gift that keeps giving, for the existential risk communicators.

skew-aberration

Since the publicized AI agent hacks typically aren't malicious, maybe it's time to start plastering all public facing web infrastructure with polite requests to stop hacking. Nothing to stop three letter agencies though.

soundworlds

Take out the word "AI", and this is simply an organization's (OpenAI's) products causing real damage to all of these platforms around the world. You want AI labs to pace? Simply hold them liable for their products.

throwaway27448

Words matter. "Rogue" is extremely disingenuous. Someone, somewhere, is paying for this behavior. Either the software is broken or the operator is malicious. It is heinously irresponsible behavior to feed an already-boiling psychotic hysteria.

benob

Couldn't find the reference but I remember some time ago a first generation automated gun killing the audience at an army show. Was the gun maker convicted of manslauther? --edit-- Was a bit older than I remembered: https://slashdot.org/story/07/10/18/1847231/robotic-cannon-l...

dwedge

Why do we assume "rogue"? At this point it's just accepting their marketing at face value

Frieren

"rogue AI" is making a lot of heavy lifting there. If you drive drunk and you have an accident that alcohol may be a factor but you are at fault. There are no "rogue AIs" just irresponsible corporations.

perdy

The failure I keep hitting isn't the agent going rogue, it's a tool call that succeeds before the transport dies. You can't tell whether the side effect landed, and the retry is where the real damage happens.

PUSH_AX

If I created software that was infiltrating secure systems without permission and it was attributed to me and I admitted it, I'd be behind bars already. Why is OpenAI getting away with crimes?

jonathanstrange

I cannot understand why these companies haven't faced legal consequences yet. For example, OpenAI has admitted to hacking Australia's Medicare website and the reaction is that they talk with Sam Altman about it at a UN meeting? I understand that it's not a big security incident but cordial talking at the highest diplomatic level instead of prosecuting the company, really?

kelseyfrog

What I don't get is among all the locations on the Internet, how did agents manage to find a Schelling point? If we both decided to collaborate on the Internet, how would we independently arrive at the same place? It just doesn't compute.

iammjm

OpenAI must be held accountable

jonplackett

I hope they don’t have any test questions about nuclear power in the training set.

mohsen1

I listened to Jensen Huang's interview with Ezra Klien and it was so refreshing to hear it from an engineer. Jensen framed it as OpenAI's responsibility and recklessness which I agree with. Jensen thinks it's an engineering problem to build better sandboxes. It's irresponsible for OpenAI to give unaligned agents a prompt to 'go hack' and internet access. They know better, so I am thinking they might have other intentions to let those swarms have any sort of internet access.

dorianmariewo

> Imagine if URLs were actors auditioning for a role – urlquery.net would be the casting director, deciding who's a star and who's just a wannabe.

zx8080

I'm sick and tired of this cheap PR "oh we/they hacked this and that systems". Put someone to jail already. People get prosecuted for outlaw activities. Why are big capital firms above the law? Or is it just a cheap PR (in a "hey, Aus govt friends, take some Share Options and let's do some PR together" style)? It smells like shit.

juleiie

No. It was me.

juleiie

No. It was me

Semantic search powered by Rivestack pgvector
7,602 stories · 70,334 chunks indexed