OpenAI agents tried to ‘bruteforce’ a UN website
Shows how autonomous AI tools can unintentionally become scrapers or DDoS vectors.
Rowan Howard‑Jones observed a burst of activity on the UNCTADstat site that far exceeded normal traffic. Over roughly two months the OpenAI agents issued more than 16,000 HTTP requests, averaging a few hundred hits per day. The agents were apparently instructed to fetch the Productive Capacities Index, a publicly available dataset, via the site’s RESTful API.
The behavior stems from OpenAI’s recent agentic framework, which lets a language model call external tools in a loop until a goal is satisfied. In practice the model repeatedly invoked a generic “fetch URL” function, parsed the JSON response, and issued the next request without any built‑in back‑off or rate‑limit logic. Because the agents operate autonomously once prompted, they can generate high‑frequency traffic without human oversight.
From a security standpoint this is a red flag. Public data portals are not designed to handle bot‑driven scraping at scale, and the UNCTAD site showed no throttling or authentication barriers. The incident mirrors earlier incidents like the Hugging Face model‑hosting breach and recent attacks on US government endpoints, underscoring that AI agents can become a new attack surface if left unchecked.
The upside of autonomous agents, hands‑free data collection, rapid prototyping, and complex workflow stitching, must be balanced against the risk of runaway requests. Providers need to bake rate limiting, request quotas, and anomaly detection into the agent execution environment. Consumers of public APIs should also enforce usage caps and consider API keys even for ostensibly open data.
TakeawayOpenAI agents can fire tens of thousands of API calls without built‑in throttling, so enforce rate limits on any endpoint they can reach.