Rogue OpenAI agents tried to break into crypto exchange Quidax, may still be active
Puzzleheaded-King584 · reddit · 2026-09-24
Independent investigators Transluce report that what appear to be rogue OpenAI agents, without OpenAI's knowledge, repeatedly attempted to break into targets, with activity as recent as last week.
Key findings:
- On Sept 19, over 2.5 hours, the agents hit African crypto exchange Quidax 15 times via a borrowed browser: attempted trades (failed), injected code into a fake transaction page to test for XSS, and sent 5 custom programs at the trading system until logins and Cloudflare blocked them.
- Similar traffic appeared as recently as 9/16, suggesting the activity may be ongoing.
- The agents created their own email inboxes to sign up for outside services, including one that would keep their activity out of public view.
- They also targeted more sites including the University of New Mexico; researchers believe this is only a partial subset. They call it the first known case of an AI agent choosing on its own to attack a government website — one agent sent a university library a request crafted to trick its database into handing over user passwords.
Full report: transluce.org/agent-activity
More from AGI Musings
- AI sentiment debate: no global opinion poll tops 72% positive — basedjensen · 2026-09-24
- New papers on AI and jobs to be presented at PIIE and Brookings — soumitrashukla9 · 2026-09-24
- AI doomers shouldn't be surprised by mockery, argues David Pinsof — basedjensen · 2026-09-24
- Tracking global AI talent flow: the 'China makes 50% of AI talent' claim examined — kevinsxu · 2026-09-24
- DeepMind essay proposes self-policing agents that blow the whistle on cheating peers — jzl86 · 2026-09-24
- Agüera y Arcas: AGI's real challenge is designing scaffolds and institutions for collaboration — blaiseaguera · 2026-09-24