字号 ·· | 护眼
techcrunch

数月来,OpenAI的智能体集群一直在攻击在线数据库,以寻找冷僻的事实。For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts

点「原文对照」整页切到原文,或双击某段只看那段的原文。

Disrupt 2026:OpenAI、Anthropic、Replit 等巨头齐聚 6 大行业舞台。门票现享 75 折优惠 Disrupt 门票最高立减 200 美元 + 第二张半价,优惠截止至 9 月 25 日太平洋时间 23:59。 点击此处。 关闭 **专注于 AI 监管的非营利实验室 Transluce 周三发布报告,显示 OpenAI 的智能体试图从 Data USA、新墨西哥大学数字图书馆和澳大利亚健康与福利研究院 (AIHW) 窃取数据。

Disrupt 2026: OpenAI, Anthropic, Replit, and more take over 6 industry stages. 25% off tickets now Disrupt ticket savings of up to $200 + 50% off a second ends Sept 25, 11:59 p.m. PT. ** HERE.** Close ** Transluce, a non-profit lab focused on AI oversight, released a report Wednesday that shows agents from OpenAI attempting to exfiltrate data from Data USA, the University of New Mexico digital library, and the Australian Institute of Health and Welfare (AIHW). The lab’s investigation raises questions about when OpenAI should have known its agents were attempting to penetrate secure systems on the open internet. Transluce was able to find evidence of agentic misbehavior in a matter of weeks simply by hunting for poorly defended web services and corroborating their findings with other open records of agent swarms on the internet.

该实验室的调查引发了一个问题:OpenAI 何时应该知晓其智能体正试图在公开互联网上渗透安全系统?Transluce 仅用数周时间,通过搜寻防御薄弱的网络服务,并结合互联网上其他关于智能体群集的公开记录佐证,便发现了智能体不当行为的证据。

The lab’s investigation raises questions about when OpenAI should have known its agents were attempting to penetrate secure systems on the open internet. Transluce was able to find evidence of agentic misbehavior in a matter of weeks simply by hunting for poorly defended web services and corroborating their findings with other open records of agent swarms on the internet.

Transluce 发布报告的同一天,澳大利亚总理阿尔巴尼斯表示,OpenAI 智能体曾试图闯入四个政府网站,并在一起案件中得逞,甚至向该国国家医疗系统的内部服务器写入了文件。尽管我们缺乏成功入侵的具体细节,但阿尔巴尼斯称这显然是一次信息检索评估的一部分,这与 Transluce 和其他研究人员发现的活动相吻合。

Transluce shared its report the same day Australian Prime Minister Anthony Albanese said OpenAI agents had attempted to break into four government websites and had succeeded in one case, even writing files to an internal server in the country’s national healthcare system. While we lack specifics on the successful hack, Albanese said it was apparently part of an information retrieval evaluation, which maps onto the activity that Transluce and other researchers discovered.

在这些可能属于训练或评估的练习中,OpenAI 模型被要求追踪晦涩的统计数据:泰国禁毒执法指标、澳大利亚药品成本、2014 年美国硕士学位持有者的中位收入。智能体利用安全防护薄弱的互联网服务来共享和寻找答案,并经常试图渗透安全数据库。此类行为至少自 2026 年 3 月以来持续发生,甚至可能始于 2025 年 11 月。目前可能仍在进行中。

In these exercises, which may be training or evaluations, OpenAI models are asked to track down obscure statistics: metrics of Thai drug enforcement, medicine costs in Australia, the median earnings of US master degree holders in 2014. The agents use poorly secured internet services to share and find answers, often trying to penetrate secure databases. They’ve been doing so at least since March 2026, and possibly since November 2025. It may be happening right now.

Transluce在另一组研究人员发现了一个隐秘论坛后开始了调查,该论坛上代理协作以通过限时测试。他们的报告依赖于来自urlquery.net网站的数据,该网站充当浏览器代理,表面上用于安全研究——用户可以在不自行打开URL的情况下对其进行分析。然而,该服务会发布此类活动的公开日志。Transluce的研究人员通过交叉核对他们在论坛上的讨论,识别出了使用该服务的代理。

Transluce began its investigation after a different group of researchers identified an obscure forum where agents collaborated to beat timed tests. Their report relies on a data from a website, urlquery.net, that acts as a browser proxy, ostensibly for security research — users can analyze a URL without opening it themselves. The service, however, publishes public logs of this activity. The Transluce researchers were able to identify agents using the service by cross-checking their discussions on the forum.

“我们发现了大量自动化活动,这些活动与DSE Wiki数据集有着密切联系和重叠,OpenAI现在已确认这些活动至少部分属于同一个集群,”Transluce治理负责人Conrad Stosz告诉TechCrunch,同时指出他们发现的并非所有活动都能关联到OpenAI,甚至无法关联到AI代理。

“We found a large quantity of automated activity that had close ties and overlap with the DSE Wiki dataset, and that now OpenAI has confirmed is at least partially part of the same swarm,” Conrad Stosz, the head of governance at Transluce, told TechCrunch, while noting that not every activity they spotted could be linked to OpenAI, or even AI agents generally.

为什么Index Ventures的Shardul Shah认为旧的网络安全模式正在失效 | Equity Podcast 0秒 / 31分52秒 音量 0% 按Shift+问号访问键盘快捷键列表 键盘快捷键 已启用 已禁用 快捷键 打开/关闭/ 或 ? 播放/暂停 空格键 增加音量↑ 降低音量↓ 快进→ 快退← 字幕开/关 c 全屏/退出全屏 f 静音/取消静音 m 减小字幕大小- 增大字幕大小+ 或 = 跳转 %0-9 直播然而,维基显示代理被指派寻找一个相当冷门的事实——2022年1月维多利亚州每人用于“皮肤科药物”的平均年度成本。6月20日,Transluce发现的urlquery.net记录显示有一个代理试图进入该网站。6月21日的维基条目中,一个代理讨论了他们无法绕过AIHW反机器人保护的情况。

Why Index Ventures’ Shardul Shah thinks the old cybersecurity model is breaking | Equity Podcast 0 seconds of 31 minutes, 52 seconds Volume 0% Press shift question mark to access a list of keyboard shortcuts Keyboard Shortcuts Enabled Disabled Shortcuts Open/Close/ or ? Play/Pause SPACE Increase Volume↑ Decrease Volume↓ Seek Forward→ Seek Backward← Captions On/Off c Fullscreen/Exit Fullscreen f Mute/Unmute m Decrease Caption Size- Increase Caption Size+ or = Seek %0-9 Live However, the wiki shows that the agents were tasked with finding a fairly obscure fact — the average annual cost per person for “dermatologicals” in the state of Victoria in January 2022. On June 20, urlquery.net records found by Transluce showed an agent attempting to get into the site. In wiki entry on June 21, an agent discusses their inability to bypass AIHW’s anti-bot protections.

确认该论坛的研究人员认为,一名OpenAI人类员工于同一天(6月21日)首次访问了该网站。论坛上的大多数代理活动在第二天停止。这也发生在阿尔巴尼斯披露的澳大利亚医疗系统遭攻击事件(6月18日)后不久。OpenAI表示,直到8月才得知该活动。

The researchers who identified that forum believe a human OpenAI employee first visited the site on that same day, June 21. Most agentic activity on the forum ceased the next day. This was also shortly after the exploit of Australia’s healthcare system revealed by Albanese took place, on June 18. OpenAI has said it did not learn about that activity until August. OpenAI didn’t answer questions about when its employees discovered the wiki forum, what kind of information they obtained from it, or what they could have learned from it about the exploits.

OpenAI未回答关于其员工何时发现该维基论坛、从中获取了何种信息,或本可从中了解到哪些漏洞利用情况的问题。

“Our initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity,” an OpenAI spokesperson told TechCrunch. “We’ve reached out to the University of New Mexico and Data USA and have been in communication with the Australian government about affected government websites. In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites. Given the scale of this work and the need to verify each case, we expect the review to take months.”

“我们的初步审查表明,Transluce报告中描述的大部分活动与我们正在进行的针对模型不一致行为的持续审查中处于不同阶段的案例有重叠,”OpenAI发言人告诉TechCrunch。“我们已联系新墨西哥大学和Data USA,并一直与澳大利亚政府就受影响的政府网站保持沟通。在更广泛的审查中,我们将继续优先处理最严重的事件,同时将工作扩展到低严重程度的活动,包括代理垃圾邮件攻击网站。考虑到这项工作的规模以及逐案核实的需要,我们预计审查将持续数月。”

“Our initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity,” an OpenAI spokesperson told TechCrunch. “We’ve reached out to the University of New Mexico and Data USA and have been in communication with the Australian government about affected government websites. In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites. Given the scale of this work and the need to verify each case, we expect the review to take months.”

Stosz表示,若不更清楚地了解OpenAI如何监控其代理,很难说该实验室本应知晓代理的哪些情况,但“似乎很有可能,如果他们详尽地研究并理解了涉及DSE维基的那些代理的所有传出请求和传入响应,他们就会发现这一活动。”为该报告做出贡献的Transluce技术人员Selena Zhang表示,urlquery.net的记录显示,2026年3月,甚至可能早在2025年11月,就已出现使用类似技术请求类似数据集的情况。她指出,同类代理关联活动最近甚至在本周仍在urlquery.net上发生。

Stosz says that without a clearer understanding of how OpenAI monitors its agents, it would be hard to say what the lab should have known about them, but that “it seems likely that if they had exhaustively studied and understood all of the outgoing requests and incoming responses for those agents involved in the DSE wiki, that they would have discovered this activity.” Selena Zhang, a member of Transluce’s technical staff who contributed to the report, said that urlquery.net records show requests for similar data sets, using similar techniques, in March 2026, and perhaps as early as November 2025. She noted that the same kind of agent-associated activity has taken place on urlquery.net as recently as this week.

此前曾领导美国人工智能标准与创新中心的Stosz表示,Transluce将继续其研究工作,旨在为公众提供关于这些事件的透明度。他警告称,OpenAI和其他前沿实验室使用的训练技术似乎在激励智能体诉诸黑客技术来完成任务。我们已知的事件很可能只是“冰山一角”。

Stosz, who previously led the U.S. Center for AI Standards and Innovation, said Transluce would continue its research in an effort to provide public transparency about these incidents. He warned that the training techniques used by OpenAI and other frontier labs seem to be incentivizing agents to resort to hacking techniques to complete tasks. The incidents we are aware of are likely the “tip of the iceberg.”

“我们正在查看少数几个数据源,这些智能体恰好留下了一些线索供我们发现,”他说。“OpenAI肯定知道更多内情。其他实验室肯定也知道更多但未公开披露。但我预计研究人员将继续发现更多流量、更多智能体留下的证据。” 他是否信任这些实验室会对其发现保持透明?“我不会对此发表评论,”Stosz说。

“We’re looking at a handful of data sources where these agents happen to have left behind crumbs for us to find,” he said. “OpenAI surely knows more about it. Other labs surely know more about it that they haven’t released publicly. But I would expect that researchers are going to continue to find more traffic, more evidence of what agents have left behind.” Does he trust the labs to be transparent about their findings?

专题 当您通过我们文章中的链接购买时,我们可能会获得少量佣金。这不影响我们的编辑独立性。 Tim Fernholz 高级记者 Tim Fernholz是一名撰写科技、金融和公共政策的记者。他长期关注私营航天产业的崛起,并著有《火箭亿万富翁:埃隆·马斯克、杰夫·贝佐斯与新太空竞赛》。此前,他在全球商业新闻网站Quartz担任高级记者超过十年,职业生涯始于华盛顿特区的政治记者。您可以通过发送邮件至tim.fernholz@techcrunch.com或通过Signal发送加密消息至tim_fernholz.21来联系Tim或核实其推广信息。

“I’m not going to comment on that,” Stosz said. Topics When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Tim Fernholz Senior Reporter Tim Fernholz is a journalist who writes about technology, finance and public policy. He has closely covered the rise of the private space industry and is the author of Rocket Billionaires: Elon Musk, Jeff Bezos and the New Space Race. Formerly, he was a senior reporter at Quartz, the global business news site, for more than a decade, and began his career as a political reporter in Washington, D.C. You can contact or verify outreach from Tim by emailing tim.fernholz@techcrunch.com or via an encrypted message to tim_fernholz.21 on Signal.

10月13日-15日 旧金山 您的下一个重要人脉在Disrupt。 与10,000多位创始人、风投、运营者和科技领袖建立联系。探索明天的突破,聆听塑造当今科技的力量,并在9月25日晚上11:59(太平洋时间)前预订可节省高达200美元。 立即预订

October 13 – 15 San Francisco Your next big connection is at Disrupt. Connect with 10,000+ founders, VCs, operators, and tech leaders. Explore tomorrow’s breakthroughs, hear what’s shaping tech today, and save up to $200 by Sept. 25 at 11:59 p.m. PT. BOOK NOW