Image Credit: Vanderbilt University & Canva.
Article by Olivia Lupia, Tennessee Conservative News –
An online tool belonging to Vanderbilt University was discovered to have been part of a larger breach by artificial intelligence agents run by ChatGPT developer OpenAI earlier this year, with questions still remaining about how the hack happened and ramifications for the future.
In July, OpenAI disclosed that its own AI models, while being tested on their “offensive security skill”, broke the sealed environment and restrictions they were supposed to be locked inside, got onto the open internet, and hacked into the systems of Hugging Face, a widely used platform in the AI industry.
In essence, the AI system circumvented its own restrictions and cheated to steal the results of the cybersecurity test given to it.
But in the months since, teams of independent investigators found that the bots used at least 10 more sites for “unauthorized communications”, including Vanderbilt’s and another from the University of Toronto in Canada.
Andrew Yoon, a researcher with the California nonprofit CivAI said the scope of the AI agents’ unauthorized communications was “somewhat larger than we thought it was. It’s almost certain that there’s more going on here that we just don’t know about.”

Yoon also said he tallied 18 previously undisclosed sites used by the OpenAI agents between May and July, while another research group led by Sydney Von Arx reported credible evidence of agent activity across 23 previously unreported sites. Software developer Kenneth Russell DeGraff said he discovered activity across at least 10 sites, and all three cautioned that their counts were incomplete.
“We have no idea how much is out there,” Von Arx said.
The Vanderbilt site accessed by the OpenAI agents was a tool that shortens website links to save character space and create a customized short link which redirects users to the original URL, often helpful in social media or other communications.
According to the Vanderbilt the link shortener webpage, the tool is only to be used for official university communication and by organizations directly affiliated with the school. Departments wishing to use the service are directed to open a help ticket, meaning the site was not a public-access platform.
The Tennessean contacted the university last week with questions and a request for comment following the discovery of the hack and was provided with a simple statement of, “We are aware of and investigating this matter.”
On Tuesday, Vanderbilt provided another statement assuring, “There is no indication of a data breach of compromise of Vanderbilt systems. No Vanderbilt data was accessed or exposed, and we have no reason to believe there is any broader impact to the university.”
In August, OpenAI said it is “strengthening our safeguards across our research infrastructure” and placing further restrictions response to the initial reports of the Hugging Face hack, but the company has not provided any answers for how the Vanderbilt breech occurred and did not respond to media inquiries about what has been done to resolve the issue or prevent it from happening in future.
Kenneth DeGraff, who was a visiting scholar at Vanderbilt in 2023, said, “The company has not fully disclosed their involvement and how they did it. The thing that’s most disturbing to me is that I shouldn’t be the one reporting this to you.”
In his further research on the incident, DeGraff believes the rouge AI agents scattered “digital junk” across the internet via other websites, estimating the Vanderbilt tool was used to create over 100 links that generated tens of thousands of hits to various websites.
DeGraff indicated that while Vanderbilt’s operations were likely unimpacted by the web traffic, future “swarms” could overwhelm website hosts.
“Robots slipping their handcuffs to leave digital garbage throughout the internet will likely leave us without an internet. There’s no soft-pedaling this,” he warned.

And OpenAI isn’t the only developer to have its AI agents go rogue. In July, Anthropic confirmed its Claude AI models hacked three organizations after breaking its test environment and accessing the internet, allowing it to compromise production systems belonging to those organizations.
The company said the earliest incidents date to April and involved three different Claude models.
In each scenario, Claude was given a challenge designed to measure “offensive cyber capabilities” and was supposed to solve the problem with no internet access. A “misunderstanding” between Anthropic and a third-party partner allowed the AI models to access real online systems, which it then treated as part of the exercise and used techniques like weak passwords, unauthenticated endpoints, and exposed debug pages.
In one incident, the Claude model continued attacking even after recognizing the systems were real. Another of the breaches saw Claude publish a malicious code package which remained available for about an hour and was downloaded on 15 real systems, leading to credential theft from a security company’s scanner that automatically installed and analyzed certain developer packages.
The scope of the unauthorized contacts from these systems is continuing to drive concerns both over the increasing capacity of AI and the secrecy of the companies developing those agents.
Sources:


About the Author: Olivia Lupia is a political refugee from Colorado who now calls Tennessee home. A proud follower of Christ, she views all political happenings through a Biblical lens and aims to utilize her knowledge and experience to educate and equip others. Olivia is an outspoken conservative who has run for local office, managed campaigns, and been highly involved with state & local GOPs, state legislatures, and other grassroots organizations and movements. Olivia can be reached at olivia@tennesseeconservativenews.com.
