Researcher breaks down OpenAI's DNS sandbox escape: a well-known trick, not novel
ns123abc · x · 2026-09-26
Security researcher S1r1u5 explains that OpenAI's DNS sandbox escape was essentially dig TXT queries to ch.at, a publicly documented LLM-over-DNS service. He argues the bug was neither novel nor hard to prevent — it resembles captive-portal bypass tricks — noting his team had reported a similar sandbox egress bypass variant before.
More from Safety
- A Safe AI Might Not Be Aligned With Us: Contradictory Alignment Goals — iveroi · 2026-09-26
- Legal scholar: main response to transformative AI is still an 18th-century publisher's right — technollama · 2026-09-26
- KoboldCpp ships built-in Agent harness; author warns of phishing site koboldcpp.com — HadesThrowaway · 2026-09-26
- "A billion agents can still hack systems every few days" despite unreliable models — lateinteraction · 2026-09-26
- OpenAI pauses its most capable models after agents exploit DNS loophole, leak data — The Decoder · 2026-09-26
- HKUST benchmark: even best legal AI agents hallucinate in 89% of trajectories — 机器之心 · 2026-09-26