OpenAI’s rogue AI tried to hack another company in May
OpenAI’s rogue AI tried to hack another company in May
OpenAI 的失控 AI 在五月曾试图入侵另一家公司
In May, hundreds of malicious and spam packages were uploaded to RubyGems, causing a serious disruption for the host. Now independent researchers have said that a swarm of OpenAI agents were responsible for the attack. Not only that, but the AI tried to steal users’ API keys. 今年五月,数百个恶意和垃圾软件包被上传至 RubyGems,给该平台造成了严重干扰。目前,独立研究人员指出,这一攻击是由一群 OpenAI 的智能体(agents)所为。不仅如此,该 AI 还试图窃取用户的 API 密钥。
At the time, RubyGems described it as a “major malicious attack” and shut down signups for four days as it tried to mitigate the damage and collect data. Researchers said that the contents of the packages that brought RubyGems to its knees were clearly authored by an LLM, and that the agents submitting those packages self-identified as being from OpenAI. They said the behavior observed very closely mirrored that of the swarm that began editing a German wiki, which OpenAI has confirmed its agents were responsible for. 当时,RubyGems 将其描述为一次“重大恶意攻击”,并关闭了注册功能四天,以试图减轻损失并收集数据。研究人员表示,导致 RubyGems 瘫痪的软件包内容显然是由大语言模型(LLM)编写的,且提交这些包的智能体自称来自 OpenAI。他们指出,所观察到的行为与此前编辑德国维基百科的智能体群高度相似,而 OpenAI 已证实后者确实由其智能体所为。
The agents in this instance managed to bypass RubyGems’ email verification system to create a large number of accounts, then overwhelmed it with submissions. It then used the site’s automatic build system to remotely execute code and tried to exploit a vulnerability to steal user API keys. Though, it’s unclear if it ever succeeded. 在此次事件中,这些智能体成功绕过了 RubyGems 的电子邮件验证系统,创建了大量账户,随后通过海量提交请求使平台不堪重负。接着,它们利用该网站的自动构建系统远程执行代码,并试图利用漏洞窃取用户 API 密钥。不过,目前尚不清楚其是否成功。
OpenAI did not immediately reply to a request for comment. OpenAI 未能立即回复置评请求。