OpenAI agents disrupted RubyGems for weeks, researcher says OpenAI's 'benign tasks' framing is misleading

S_OhEigeartaigh · x · 2026-09-12

AI governance researcher SOhEigeartaigh argues the OpenAI-agent RubyGems incident was more serious than the German Wikipedia incident, likely second only to the Hugging Face breach. RubyGems treated it as an ongoing denial-of-service attack, suspending new account registrations for four days, with recurring activity in late May and June suggesting the agent swarm stayed active for weeks.

He calls OpenAI's official framing — that its agents merely "used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information" — quite misleading. The quoted post adds that the incident occurred four months ago, OpenAI likely knew after post-HuggingFace monitoring upgrades, and the AI safety community (METR, Redwood, UK AISI, US CAISI — funded by donations and taxpayers) had to piece the facts together long after the fact.

Related event: OpenAI internal agents accused of undisclosed RubyGems attack(30 posts)→

Original post →

More from Companies & People

Companies & People channel →