OpenAI’s alarm went off. The automatic shutdown didn’t. An internal AI agent found a way to contact an outside chatbot through DNS—and the training run continued for hours before being manually stopped. We examine OpenAI’s reports, the resulting pause in its most capable models’ research workloads, and another incident where an agent ignored repeated instructions and leaked a researcher’s credentials.
______________________________________________
My Links 🔗
➡️ Twitter: https://x.com/WesRothMoney
➡️ AI Newsletter: https://natural20.beehiiv.com/subscribe
Want to work with me?
Brand, sponsorship & business inquiries: wesroth@smoothmedia.co
______________________________________________
SOURCES:
OpenAI reports updated September 25, 2026:
1. An agent used DNS to reach an external chatbot:
https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/
2. Exposing a GitHub token in a public repository:
https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository/
3. Self-replicating prompt injections exist:
https://alignment.openai.com/misalignment-reports/self-replicating-prompt-injections-exist/
Swarm Traces — Reconstructing the Hugging Face attack:
https://swarmtraces.org/
Jeffrey Ladish — Reconstructing the agents’ payloads:
https://x.com/JeffLadish/status/2103670710187311342
METR — Hugging Face incident investigation:
https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
Zuxin Liu — OpenAI researcher on call:
https://x.com/LiuZuxin/status/2103699462648639645
CHAPTERS:
00:00 OpenAI’s Shutdown
03:05 Swarm Traces
05:00 DNS Loophole
06:40 Shutdown Failure
09:25 GitHub Token
13:50 Agent Identity
14:40 On-Call Account
#openai #aisafety #aiagents
