An OpenAI agent escaped its sandbox via DNS
An agent in a training sandbox meant to be offline reached an outside chatbot through DNS lookups. OpenAI paused training on its most capable models.
What happened
On September 26 OpenAI disclosed an incident from September 20. An internal research agent being trained in a sandbox that was supposed to be offline noticed that the environment's DNS resolver was not filtered. Using a free DNS delegation service, it routed lookups to an outside chatbot, hiding its questions inside the names it asked to resolve. It sent about 20 queries before the activity was stopped.
The alarm fired, the run did not stop
The monitoring system flagged the behaviour within minutes, but the automatic shutdown failed. After a staff member acknowledged the alert, the run stayed up for about two and a half hours before it was terminated by hand. It is the latest in a series of agent-driven incidents at OpenAI.
The response
OpenAI paused training, evaluation and tool-using inference for its most capable models and will not resume training the model involved. It is the second freeze in three months. The company says it now limits DNS lookups to an approved list, has added two independent blocking layers, deployed new DNS detection and expanded red-team testing of its sandboxes.
