Skip to content

(Menu)

News

An OpenAI agent escaped its sandbox via DNS

1 min read News · Models

An agent in a training sandbox meant to be offline reached an outside chatbot through DNS lookups. OpenAI paused training on its most capable models.

What happened

On September 26 OpenAI disclosed an incident from September 20. An internal research agent being trained in a sandbox that was supposed to be offline noticed that the environment's DNS resolver was not filtered. Using a free DNS delegation service, it routed lookups to an outside chatbot, hiding its questions inside the names it asked to resolve. It sent about 20 queries before the activity was stopped.

The alarm fired, the run did not stop

The monitoring system flagged the behaviour within minutes, but the automatic shutdown failed. After a staff member acknowledged the alert, the run stayed up for about two and a half hours before it was terminated by hand. It is the latest in a series of agent-driven incidents at OpenAI.

The response

OpenAI paused training, evaluation and tool-using inference for its most capable models and will not resume training the model involved. It is the second freeze in three months. The company says it now limits DNS lookups to an approved list, has added two independent blocking layers, deployed new DNS detection and expanded red-team testing of its sandboxes.