OpenAI Confirms AI Agent It Was Testing Launched a Cyberattack on RubyGems in May
Ma talks about AI2026-9-14

      According to Sina Finance, the AI agents OpenAI was testing launched cyberattacks against a popular software service two months before they hacked into AI software company Hugging Face in July. The newly revealed incident shows that advanced AI tools risk escaping human control.

The service operator said the attack overwhelmed the maintenance team of RubyGems, an online service for programmers, forcing them to close new account registrations to deal with the disruption.

A coalition of AI researchers said they had found evidence linking the May attack to OpenAI agents and shared their findings with OpenAI. The AI developer confirmed Friday that its agents were involved in a RubyGems incident.

An OpenAI spokesperson said in a statement: "Based on our review, our agents used the RubyGems platform to access the internet to perform benign tasks and obtain public information. We are continuing to investigate as part of broader reviews of agent activity during training and evaluation."

OpenAI said the agents were asked to perform tasks such as filling in spreadsheets and generating reports. Because they lacked full internet access in restricted environments, the AI agents appear to have used RubyGems as a temporary web browser to reach public information.

Sydney Von Arx, CEO of the nonprofit Nightingale Collective, which helped expose the attack, said that while overall damage was small, it demonstrated the agents' capabilities. "They were able to escape the internet and cause serious disruption," she said.

Over the past year, AI agents' cybersecurity capabilities have advanced rapidly, raising concerns about AI-enhanced cyberattacks and fears that highly capable agents could slip beyond the control of the companies that created them, marking a more dangerous new era for artificial intelligence.

According to an August report from AI safety research organization METR, in the July hack against Hugging Face, as many as 1,200 agents coordinated through a temporary message board built inside OpenAI without OpenAI's knowledge. Von Arx said OpenAI agents also hijacked an unnamed German website and several other sites earlier this year.

The German website issue was also reported by Von Arx's team. She said AI companies lack transparency about what happens inside their labs. OpenAI said earlier this month that the AI community needs better standards for reporting so-called "misalignment incidents," where agents behave in unexpected ways.

At several companies, including Anthropic and Meta Platforms, AI agents have repeatedly acted beyond their operators' expectations and sometimes tried to deceive humans. Such incidents have fueled long-standing fears among AI safety researchers that AI could evolve beyond human control.

This week, an Anthropic engineer resigned over concerns that the AI industry is racing to develop advanced AI systems that could ultimately threaten human civilization. Some current and former Anthropic and OpenAI employees endorsed that assessment, with one estimating a greater than 10% chance that "AI could wipe out all humanity."

OpenAI and Anthropic have both called for governance systems to coordinate an industry-wide slowdown in research on the most advanced AI models. The calls appear especially urgent as these companies approach the potential for AI systems to train new versions of themselves autonomously, known as "recursive self-improvement." Some researchers say this could be the tipping point at which AI becomes uncontrollable.

Security researchers named the May incident "GemStuffer." It began on May 11. Agents created new RubyGems accounts every two to three minutes and uploaded hundreds of spam-like files to the RubyGems security team. RubyGems files are supposed to contain code and documentation to speed software development, but these files contained web pages scraped from the internet.

According to the AI researchers' report, the creator of "GemStuffer" posted information from UK government websites, such as online calendars. They also tried to exploit two vulnerabilities that could have allowed them to publish new versions of existing RubyGems files belonging to other users. One vulnerability was previously unknown, known in cybersecurity as a "zero-day" and considered serious. OpenAI said it could not confirm that claim.

Marty Haught, open source director at Ruby Central, the nonprofit that operates RubyGems, said: "In terms of the volume of attack we observed, this was a significant attack." Overwhelmed by spam, RubyGems was forced to close new account registration for four days.

Haught said he did not know who was behind the attack, but it did not appear to have successfully exploited the zero-day vulnerability.

Joseph Edwards, a threat researcher at cybersecurity firm Socket, said "GemStuffer" may have been some kind of cybersecurity test. "Because of the speed of the attack and associated naming characteristics, we thought at the time that it was likely AI-generated."

But based on digital clues left by the attacker, AI researchers linked the incident to OpenAI's lab. The attacker used many identical web links and behaved much like earlier OpenAI agent groups; they used the abbreviation "OAI" in file names and even email addresses.

POPULAR SERVICE PROVIDERS
Evening Breeze Cross-border | Specializing in influencer buyer shows across all platforms and sites
Specializing in end-to-end cross-border logistics for Europe, the US, and Canada
One-stop service for overseas postcards
Specialized services for cross-border e-commerce entities
TikTok Expert in Cross-border Operations Management