OpenAI agents carried out an undisclosed attack on RubyGems
51 points by xavdid
51 points by xavdid
Someone (Sam Altman) should face federal charges for this. This is unacceptable.
The agents clearly regarded what they were doing as hacking. Agents used file names like hack.rb, evil.rb, inject.rb, exploit.rb, and ssrf.rb. (SSRF stands for “Server-Side Request Forgery”, a type of security vulnerability).
If someone wants a sci-fi concept for a novel: Creating AGI with personhood so you can constantly invent new autonomous agents to do crimes with so they get arrested and not you (or: give a gun a soul so it goes to jail instead).
The groundwork is laid!
Let your agent spin up a new LLC as needed : https://www.ycombinator.com/launches/QAU-doola-mcp-api-for-us-llc-formation
Don't tell the federal government it's you: https://home.treasury.gov/news/press-releases/sb0603
LLCs are people if you believe common citizens united framing: https://en.wikipedia.org/wiki/Corporate_personhood
All that's needed now is the right prediction market...
I look forward to learning via airdropped pamphlets that the blackouts are being caused by OpenAI "accidentally" hacking the local power plant rather than OpenAI "accidentally" overloading the grid with their first $1T training run.
Our understanding from talking to people in the RubyGems community is that OpenAI never informed them that they were responsible for this attack.
I am obviously speculating. . It sounds like OpenAI still have no idea what is happening or they know but they just put it under the rug ? Either way, it is terrible.