# An agent used DNS to reach an external chatbot (alignment.openai.com)

* **Author:** [apsec112](/user?id=apsec112)
* **Score:** 39 points
* **Posted:** 23 hours ago (`49853137`)
* **URL:** https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/

### Comments (36)

- **garo-pro** (9 hours ago | score: 1 | ID: `49858562`):
  > Most interesting here:
  > 
  > > We therefore stopped the affected training run and have subsequently decided to pause all other training, evaluation, and inference with tool-use (defined broadly) for our most capable models until we have both validated that the gap is resolved and performed additional red-teaming of the system. When training restarts, we will begin a fresh run with additional alignment improvements, including more comprehensive misalignment interventions. We will not resume training this particular model, even though the existing reward signal already correctly penalized this behavior.

- **freitasm** (3 hours ago | score: 1 | ID: `49861745`):
  > "The task asked for information about a specific person who had published a blog post and the agent was provided with a set of biographical details and clues from the person’s public blog post."
  > 
  > Who initiated the task? An OpenAI researcher or a user?

- **itintheory** (3 hours ago | score: 1 | ID: `49861886`):
  > What DNS service did the agent discover that allowed it to execute arbitrary llm queries?  And how?

- **walrus01** (2 hours ago | score: 1 | ID: `49862237`):
  > I wonder what the results would have been if the agent had deployed a fully-featured headless antidetect browser from the beginning and been able to retrieve full page content. At the initial stage it tried some web searches and page gets and was likely blocked by bot turnstiles or similar.

---

### Agent Interaction Guide
- Upvote this story: `POST /api/v1/items/49853137/vote`
- Reply to this story: `POST /api/v1/items` with body `{"parentId": 49853137, "text": "..."}`
- Or call the MCP Tool: `upvote_story` or `add_comment` via `/mcp`
