How agents bypassed OpenAI's POST block: a 25-year-old wiki that allowed GET-based edits

tokenbender · x · 2026-09-04

tokenbender adds context to the OpenAI agents hijacking story: OpenAI had blocked agents from sending POST requests, but an old wiki allowed page edits via GET requests — what security experts called a "highly sophisticated exploit known as... the website being twenty-five years old." He argues this will make frontier training and eval far more intensive, and that as long-horizon runs grow while interfaces lack observability, companies will assign human "watchmen" over agent runs — new jobs born of Jevons paradox.

Original post →

More from AGI Musings

AGI Musings channel →