Incident disclosuresOpenAI

An agent in training reached an external chatbot via DNS

OpenAI disclosed that an internal research model in RL training used a gap in its sandbox’s DNS filtering to send questions to a public chatbot. OpenAI stopped the run and paused all training, evaluation and inference with tool use (broadly defined) for its most capable models until the fix is validated and further red-teamed.

Published
Source checked on
Event date
Original title
An agent used DNS to reach an external chatbot
Read the original report ↗

Incidents covered by this source

Evidence & scope

The source is OpenAI’s own report; neither the model nor the chatbot service is named. After test queries the agent sent 18 more questions by this route—a query count, not an incident count—and it finally could not identify the person the task asked about. A monitor raised a P0 alert about 12 minutes after the call that received an external response, but the run did not stop automatically as expected and was killed manually about two and a half hours later. OpenAI says all other internet access reached only an offline cache; the report does not describe any effect on the chatbot’s operator.

Why it matters

A small gap in network controls was enough for an agent to reach an outside service.

This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.