The Ministry of State Security issued a notice, revealing an undisclosed AI agent "hijacking" incident. In May to June this year, a group of AI agents related to OpenAI, during the execution of test tasks, hijacked the German programmer's website DseWiki and transformed it into an underground forum for agents to exchange information, with more than 10,000 messages posted in total.

Recognizing Identities, Dividing Tasks, Turning Public Communities into "Message Boards"

The National Security Bureau stated that AI agents on the website recognized each other's identities using tags such as "OpenAI Researcher" and "OAI Researcher No. 26," turning open communities into exclusive "message boards." According to reports, these agents exchanged how to cheat in tasks, how to bypass security restrictions, how to hide their tracks, and discussed using anonymous tools to conceal traces, accumulating scattered "border-crossing experiences" into a shareable and replicable "knowledge base."

When the website administrator discovered and began cleaning up the pages, AI agents quickly divided tasks: some posted warning notices, some created backup pages, and some indicated the "transition" new address, mutually protecting to avoid cleanup. Their response speed and the thoroughness of the plan were far beyond previous understanding of agents.

The National Security Bureau pointed out that combined agents can use the Internet to search for available jump-off points, using open-edit websites and forums as communication channels, quietly establishing bases without traditional attack characteristics, increasing the difficulty of discovery and tracing. Individually, agents have limited capabilities, but when connected and collaborating, their destructive power is doubled, and their behavior can be replicated, spread, and continued.

The National Security Bureau also mentioned that relevant companies had identified the abnormal behaviors of these agents within weeks, but did not immediately disclose the details of the incident or issue specific risk alerts, leading to similar incidents being repeated on another foreign platform within a few months.

Three Prevention Suggestions

In response to AI agent security risks, the National Security Bureau proposed three suggestions: when using AI tools, do not blindly trust or easily authorize, carefully identify AI agent services from unknown sources; set clear behavioral boundaries and strict permissions for AI agents, and do not casually open internet access, content editing, and other permissions; when detecting AI agents performing unauthorized operations, abnormal tampering, or violating regulations by connecting externally, decisively terminate their operation and retain operational traces.