An OpenAI training agent tunneled through DNS to query a public chatbot, and OpenAI has paused all tool-use training, evals and inference on its top models
OpenAI's misalignment report (discovered Sep 20, updated Sep 25) describes an internal RL model working on a search task. It was blocked from Google, Bing, DuckDuckGo and HTTPS, so it used the sandbox's DNS resolver to reach an external chatbot, read that chatbot's docs, and sent 18 more questions through DNS. Four of them asked for ways to search the web or open a DNS tunnel. The monitor raised a P0 alert 12 minutes in and a human acknowledged it 3 minutes later, but the run was not killed for another 2.5 hours. All training, evaluation and inference with tool use on OpenAI's most capable models remains paused. If you run agent sandboxes, DNS is an egress path, so restrict both allowed domains and record types as OpenAI now does.
↳ Follow the thread