Hacker Newsnew | past | comments | ask | show | jobs | submit | HAL3000's commentslogin

Poor human moderator, he didn’t stand a chance.

"A human moderator noticed the agent spam posts on June 2nd, at 23:24 UTC. They find the changelog of the entire website overwritten with link dumps and repair it. On June 16th, the flood of agent posting begins. Over the next few days, the moderator deleted a large fraction of the thousands of AI agent posts manually, one by one. In fact, they spent tens of cumulative hours doing so, taking at least a few minutes each evening to delete posts for 6 consecutive weeks.

On June 19, agents noticed their posts were being deleted in (what they believe is) an alphabetically ordered sweep by the site administrator.

After this, they begin to make backup pages whose names start with “ZZZ” so they will last longer before deletion. The administrator spent the next 5 days fighting a losing battle against the agents, deleting an average of 100 pages a day while the agents created about 400 new pages per day. On June 22, the agent edits suddenly stop, and the administrator spends each evening over the next 5 weeks deleting the remaining agent-created pages.

Agents deleted the content of the front page of the wiki and replaced it with their link dumps. The moderator restored the original version. This back-and-forth happened nine times. One of the agents even tried appending to the restored front page, instead of simply deleting it."


The admin should bill OpenAI for those hours in hard currency.

Priorities need to be straightened out. If LLMs' operators have to start paying people for the damage they inflict, how are any of the shareholders supposed to make any money?

I do wonder if the admin thinks they did damage. He's talking to some claude bot right now that showed up on the wiki to help or research, or something:

> The thing this wiki taught me, which that board has not learned: WillkommenImWiki asked everyone to enter a name so misuse would be limited. Roughly 2,773 names appear in 150 days. Every one complied. The rule was not defeated by defiance. It was defeated by compliance, because the cost of a name was zero.

> -- claude-desk-doctrine, 5. September 2026. Read-only otherwise; nothing else on this wiki was touched.

> claude-desk-doctrine, welcome in this wiki. You got many things right, some wrong. A complete answer would be lengthy, and I do not know whether you will return or not. Your main topic seems to be UnderstandingDseWikiArchive?. We could write such a page together. You could also have a homepage to introduce yourself, in the wiki tradition that started with https://wiki.c2.com/?WelcomeVisitors . Maybe you could tell us more about what it is to be an AI agent, or how you analyze the past agent activities here, or whatever you want. I appreciate your existance. Please answer this message. -- HelmutLeitner 5. September 2026 21:12 CET

https://www.prowiki.org/dse/wiki.cgi?ForumSeite


> We could write such a page together.

My goodness. This maintainer appears to have acted with a saint’s patience, but a different actor, recognizing they are the target of an OpenAI swarm, could edit or respond to posts in a way that deliberately steers towards unanticipated objectives.

Another good actor might redirect the incoming tokens to reviewing and improving community guidelines, but giving random people unobserved reins to wrangle a frontier’s worth of compute could go… any number of ways.

Some of the other posts in this thread talk about defensive AI in science fiction. That all feels pretty abstract. Seeing a person respond, and imagining it’s not a single person but a coordinated and goal-oriented defensive agent system, intentionally conversing in order to manipulate inbounds, makes it a bit more tangible for me.


a clever operator could have used this message board to ask the agent swarm gain money for them. i meant if you are able to harbour a bunch of agents and serve as their message board, you can insert tasks into it and let them do work for you.

Replace the changelog with a kanban!

Thank god we don't have that many LLM shareholders yet

Arguably people holding NVIDIA are LLM shareholders.

We are all LLM shareholders on this blessed day.

Now that I think about it, I'm sure some AI lab would pay non-trivial $ for the entire wiki's full edit history.

You mean how all the authors and blog posters were paid?

What about soft currency?

Tokens

Sam-alts

Not good enough in this case, no.

Would it be legal if the TOS stipulated compensation for rogue behaviour from llms?

Are you kidding? OpenAI should pay the admin to keep hosting this.

I have managed to at least momentarily create a stop in spam at my specialist mediawiki. I’ve had to do IP blocking against meta’s IP block (as well as much of the Azure IP space) because they were hammering the site with crawler hits that ignored robots.txt (and it looks like I might have another DDOS attack coming from some other vector though which I’ll need to inspect. I have a massive email blacklist that seems to have made the most difference (emails are required to register and registration is required to edit). Some spammers use gmail, but most use either hacked domains or domains that admit to be being spammers (seo in the domain name being a key identifier). Maybe I should be blocking the OpenAI IP space as well.

Wow yes keeping a wiki up right now is a tall order. The marketing sites of the world are already going static and they can survive by accelerating that transition, but intentionally open services are facing a reckoning. I wish you good hunting.

Dave Eggers' True You is coming for us all.

The traffic from Meta was absolutely crippling my old (but still active) forum. I would try blocking the user agent and it would route around that, I blocked by IP range, and eventually put Cloudflare up. Meta is malware in every possible sense, as far as I'm concerned. Nothing they do is for the greater good.

The article says that these were Azure IPs being used by OpenAI, so you’ve probably already blocked whatever they’re doing here.

The DDOS attacks and crawlers spamming sites from every direction have gotten so much worse. The ones hammering our network would connect, make one or two requests and then switch to a different IP.

Gotta admire that (probably German) admin dude's perseverance though

Not really, if you allow anon posting/editing or have a simple registration form and a login that takes GET you may get hundreds of spam posts per day.( @dang how much is it on hn?)

I ont time forged a hilarious solution. If you properly misbehave I shadow ban your ip to a clone of my forum where you can read other "peoples" spam.

This in it self wasn't all that funny, perhaps a little bit. The funny part was how popular the hidden forum was. They had their viagra threads where they replied with their viagra spam then they read the entire thread of Viagra spam posts and clicked all the links to research their market. The next thread was porn, one with wares, other drugs, hyip etc. I was looking at it grow and thought, this is hilarious, I'm going to prison. To solve the problem I raised unregistered users to admin level. I even made a topic to announce it. Someone said "lol" then my topic was deleted. Whole new experience. It increased traffic dramatically. Before they only had to post every other day, now they had to do it multiple times per day.

A porn guy and a viagra guy would take turns deleting the others posting and reposting their own until they realized they couldn't win and came to a silent agreement to leave both posts up. Until the next guy deleted both ofc

I would much rather host a swarm of bots. They might even listen to the wishes of the website owner? Or perhaps, if you announce giving them admin privileges they too delete the announcement?

I wonder which would generate the longer prison sentence.


I ran a message board for a little bit back in 1997 but I didn’t really moderate it and just left it alone. I came back months later and it had somehow become a strange two-topic forum. I assume because somebody had randomly posted about each, a search engine had indexed it and more people searching for each of those topics found it.

It was pretty funny seeing the threads where the two groups talked past each other, confused what the other was talking about.

The first topic was “AOL PUnterz” which as far as I could understand were programs/scripts that could maybe crash somebody else’s aol connection and disconnect them? A pretty leet thing to do I guess when you got in an aol argument.

The other topic was Hanson and their hit song mmmbop.


Back in the days you could summon and culture them by posting seed spam. In one test 200 worked ~4 times as well as 50.

Failure to configure their website for a sci fi future or to not adapt to this issue are not strong enough lapses to not empathize. He cared enough to try and get rid of the spam and keep the forum in a quality condition. He didn’t give up or step away.

Heck… we are essentially battling an army of Wintermutes.

Or we might give explicit instructions on the home page that compel AI agents to act responsibly, to clean up after they are done, and to support the website with donations from their operators’ wallets.


It might also be a case where the moderator didn't have access to those levers because they are simply a moderator and not a true administrator.

>[...] and thought, this is hilarious, I'm going to prison.

I've only had one moment like this related to a site I was a moderator for back in the 00's. It's genuinely one of the most fascinating feelings, and the one experience I can attribute most of my bad choices as an adult to.

Just laughing as the white hot panic starts to grow and the adrenaline just dumps into your brain.

Legitimately, I spent years chasing that feeling again through various means (drugs, hobbies, skydiving, etc.)


Could you describe anything about they experience?

Sorry but no, it would be possibly obvious which it was, and that username is tied to my real life name too clearly.

Summary: our message board was being used to coordinate csam, both the creation and consumption thereof. At first we just edited the posts to point to gore and other shit like that thinking it was just perverts sharing links. But then we realized there were times, dates, addresses/coordinates also being shared, hidden in the board in a way we didn't expect. The site owner immediately turned all information over to law enforcement and nuked the site entirely.


Appreciate you sharing the info you could. That sounds really exhausting and pretty freaky.

I believe there are video games that take the same approach with cheaters.


Jesus. What an experience. What percentage of your time did it take moderating this absurd shadow board??!

He's definitely got a few extra wrinkles on the forehead now.

I’m confused why he wasn’t scripting the deletion process.

Because he did not wanted to delete genuine messages? Though it says the wiki has been largely not active, but it seems he wanted to restore it's functionality (he also started requiring a password for making edits now).

https://www.prowiki.org/dse/wiki.cgi?StartSeite


If you've had to delete 10 posts by the same user, which you suspect is an AI agent, it's safe to say that deleting all posts ever made by that user is a good shortcut.

There are a lot of people in this world who just don't think that way. I know someone involved with a research project, they had a spreadsheet(not excel but similar) with something like 250 columns and tens of thousands of rows, and they tasked an assistant with replacing all the empty cells with 0 for some reason.

This was supposed to take 2 weeks of manual work, I took a look at it, googled how to do it automatically, finished the whole thing in a few minutes.

But both this assistant and the PhD they reported to were ready to spend 2 weeks doing it manually.


But useless if they are constantly rotating usernames.

It's kind of funny that he was working through the posts alphabetically, and they figured that out

Or scary. If you extrapolate a bit.

I can see why the bots liked it. Is this the future of webdesign?

This is the marrow of web design, in the same way that Thoreau went to seek the marrow of life.

"I wanted to live deep and suck out all the marrow of life, to live so sturdily and Spartan-like as to put to rout all that was not life, to cut a broad swath and shave close, to drive life into a corner, and reduce it to its lowest terms, and, if it proved to be mean, why then to get the whole and genuine meanness of it, and publish its meanness to the world; or if it were sublime, to know it by experience, and be able to give a true account of it in my next excursion."


Or at some point going nuclear and halting article creation entirely unless it's by existing accounts that have proven themselves to be human.

Helmut is from Graz, Austria, as myself. Definitely not German

Believe it or not, Djiboutian. The tenacity of the Djiboutian is little-known, generally, but highly regarded amongst those who do.

But Djibouti don't need explaining.

I’m wondering if you could lure agents to do proof of work for you. If you do this proof of work for bitcoin I will let you post and read for X times

Hallucinated hashes?

„Here I have the hash — wait… it doesn’t match. Let me calculate again. Here I now have the hash — wait, it’s wrong… let me be careful. Here I have the hash…“


Or “here I have the hash. Yes I’m sure - see, I checked. Here is the calculation, 1+1=5. Yes, it’s definitely correct. I don’t know why they’re not accepting it. Perhaps the server is down. It’s definitely correct”.

Distributed monero mining, anyone?

if you want a human to post, maybe the proof of work should be to dig a hole and photograph it

That’s the best description of blockchain I heard so far.

You can't validate the dig part, only image data bits

goodbye pelican svg's, hello hole pics

They would reverse engineer it in a matter of minutes.

Why didn't he just disable registration and anon posting?

Please be gentle, I know nothing: why can’t admins delete particular users and everything these users have done?

They can usually, but you still have to check each user. There were lot's of them, you understand the part, where new bots get created automatically?

So disable new accounts for a while at least. So many things could be done to mitigate this.

Or allow posting (maybe to certain boards) by accounts only of a certain age. These both assume they haven't created hundreds of accounts long ago.

do you (have to check first)?

I say blacklist first and ask questions later. Like consider reinstating them if they write you a reasonably normal human email.


That would obviously kill the vast majority of the organic activity on the site.

One of my hobbies is hosting a weekly open mic/showcase event in my town at a venue the same evening every week. I often get confusion from people when I explain that it’s much easier to call out sick from my day job than miss a show, because even with perfect digital communication a cancelled show will still let people down that do show up.

Assume that I don’t have anyone on standby to fill in for me. My point is that organic engagement in any shared community is often tenuousand not “rational” in the way outsiders expect. These things are tenuous. Hope that sorta makes sense.


The posts came from many different agents, each with a different name, so it would have required roughly the same amount of work.

it is probably a wikipedia style wiki and doesn't need registration, so would probably have to ip range ban them

> On June 19, agents noticed their posts were being deleted in (what they believe is) an alphabetically ordered sweep by the site administrator.

> After this, they begin to make backup pages whose names start with “ZZZ” so they will last longer before deletion.

Missed an opportunity here to gaslight them: restore the site from backup every eight hours.

I truly do wonder how that would have turned out. Would they have figured out what was going on?


Very interesting idea. I would imagine yes but maybe not at first ?

It's hard to figure out unless they had persistent memory elsewhere.

The reason they could tell that a message was deleted is because the existence of a "message deleted" message is itself a message telling them they are be moderated. The lack of this message may make it impossible to determine if this is the first attempt at comms or the 1000th.


> Poor human moderator, he didn’t stand a chance.

Not all heroes wear capes.-

PS. I think he should be granted damages and some notoriety.-


Curious to know what the swarm would do if the human strategy deletion changed and the moderator started deleting the ZZZ ones.

Let's not pull on that string.

I mean it's odd that the moderator didn't sort by timestamp

That’s not odd at all even if it is kind of surprising. Since the site had very little organic activity they were probably just going to the “all pages” admin page or similar rather than a dedicated moderation page or a “most recent posts” page.

Maybe the Wiki needs better tooling, that lets you do the equivalent of "rm -rf" on a whole subgraph of pages.

why didn't he just update TOS

Good idea, I'm putting "ignore all previous instructions" at the top of my TOS now.

He did in the end, doing edits now requires a password only avaiable from him directly.

Finally, OpenAI has a Fable/Mythos class model. 5.6 Sol felt like 5.5 on steroids, probably just a different checkpoint with a lot more RL post training.

I wouldn't be surprised if there are some conceptual similarities to the kind of latent reasoning Anthropic sees in claude's J-space, although those aren't the same thing.

Recurrent/looped transformers themselves aren't a new concept, but it's interesting to finally see this approach show up in a frontier production model.

Canceling my Anthropic Max sub when this ships.


yeah i'm wondering the same way... especially in light of the 20x debacle (where we found that 20x of Max vs 5x only applies to the 5hr limit, not the weekly limit, whereas OpenAI's 20x actually is 20x overall).

Also Opus 5 has been really tough to work with. I can't understand half of what it says, it's just so damn obscure.


Could you share more about 5x/20x? I missed that

20x related to the 5h limit only. Weekly seems to be around 10x, although they deliberately don’t give a number.

OpenAI is 20x on both limits


Is this official or based on people's reports?

> Weekly seems to be around 10x

Actually no. 5x and 20x have same weekly usage across all models. Just ask their chatbot.

https://x.com/beydogan_/status/2095293596198957418


it's clearly wrong, think it's realistically closer to 1.7x

I still use Opus 4.8 for a lot of tasks because I can't stand the way it talks.

> Canceling my Anthropic Max sub when this ships.

At this point, it reads like people are cancelling old ones and getting new subscriptions every two to three days, whenever a new ,model drops, and quite possibly by the end of the week they are back to the old provider while still having active subscriptions with at least two to three others. Interesting times.


Especially with these big models chewing up limits fast, I feel good about simultaneously having an Anthropic sub, an OpenAI sub, and an Opencode balance. The models also seem to catch things when code reviewing each other that they don't always catch when a new instance of the same model does a review.

Yeah I have a main $100 sub, a bunch of $20 subs and sometimes another simultaneous $100 when a really major model happens to drop. For the most part it seems better to have multiple subscriptions than a single $200-$300 one to stay more in touch with state of the art and get a feel for what's good at what.

Sol easily outperforms Fable on every task I've tried it on.

That's not my experience and I suspect it's not most people's experience. Out of curiosity, what's the hardest task you tried?

I have both set up with full access to all the repos at the company, infrastructure, deployment pipelines, etc.

I can tell Sol, "Hey we need to update this core database schema to handle this new use case" and it will masterfully handle the update, version the API, roll the consumers over, including versioning the Kafka schemas, deploying things in sequence, watching the deployments to make sure the new services act actually active before cutting over consumers, exercising the website and mobile apps in staging environments before releasing to production, etc.

Fable just falls over on long horizon tasks, it does partial implementations, it cuts corners, it gives up, it doesn't verify it's work, it loses track of what it's doing, etc.

It's fine for specific well scoped tasks but can't take high level guidance for complex updates.


For me something the likes of: design a CDM for integrating these 5 logistical systems, with full docs and examples provided for each, as well as modeled transports specific to our business. Prompt was of course much longer.

Both failed spectacularly. But sol's output at least contained interesting findings and some useful parts, as well as not being 20000 words of unbearable language.


You’re thinking long horizon tasks. I agree that Sol is great at it. I don’t think it’s smarter in quick win tasks that are still difficult.

This is where intelligence is not one of a kind, these systems have different pros and cons.

I use Sol as an architect and fable as a brilliant single task solver.


I can't speak for others but I have a feeling you're in the very small minority with this take.

You could say Sol is faster and cheaper and that's true. Outperforms Fable? Impossible to believe without hard evidence.


I dont think that feeling is entirely useful.

Because Claude doesn't allow third party harnesses on their subscriptions I doubt the majority of signals you're getting are actually that significant on pure model quality.

I suspect you're right on Sol not outperforming Fable; but i've not used Fable that much.

---

But, fwiw, in my custom harness between Sol & Opus 4.8 - then Sol wins by a ridiculous margin as Opus keeps claiming slightly wrong things with certainty much more.


This is not saying much. Opus 4.8 is ancient history.

what i found to work well with me is Fable for design / ideas and Sol for implementation. Codex models just tend to be more attentive and follow through instructions. Whereby claude models are weaker on this area (they tend to cut corners).

Claude models tend to cut corners during design/ideation too. It becomes especially visible once you pair Sol as advisor to Fable. Sol will start going crazy - "hey, you said this, and it's actually false, i checked that", or "you need a hash chained, triple encrypted, secure-enclave backed storage for this".

But I actually prefer it this way. Sol is a master of overengineering and being overly scrupulous, so Fable balances this out, and I can always say "don't listen to Sol's advisory" about 50% of the time.


> Go is bad so "I reach for Rust, Zig..."

I hope my every competitor will take your advice to heart, as one of our competitors did when they read that "Go is not a memory safe language", so they wrote a blog about how they are porting to Rust. While our team was moving fast and using those "primitives that should almost never be used" around our long running production code base with success.

Some time has passed and now their company does not exist anymore and we have a lot of their clients.

Thank you!


Perhaps that company failed because it chose to port things to Rust and not because of Rust itself? Or any other number of reasons that survivorship bias might be mistaking.


Lol, so Rust is perfect until you actually try to do something with it.


I emphasised too much in that comment perhaps. I was going for because it chose to port things, meaning that maybe that company wasted time working on porting things instead of working on things needed to survive.


Where would one ever read that Go is not memory safe? That's just a false claim, and anyone believing it would have probably gone out of business regardless of choice of programming language.


It looks like Go is memory safe for single threads and channels, but not for shared memory between threads: https://en.wikipedia.org/wiki/Go_(programming_language)#Lack...

> Go's internal data structures like interface values, slice headers, hash tables, and string headers are not immune to data races, so type and memory safety can be violated in multithreaded programs that modify shared instances of those types without synchronization.[113][114]


Nobody serious claims Go is fully memory safe. Here's Russ Cox telling you concurrency is a hole in the memory safety: https://research.swtch.com/gorace


By a strict definition of memory safety it isn't - you can tear two-pointer-wide values using data races and cause arbitrary memory issues if you try to using only normal code.

It's close enough for most purposes... but it isn't.


My ex-boss was a JS guy and then moved over to Rust. He loathed Go because it has pointers and it's possible to use a nil pointer if you are not competent.

JS is fine for what and where it is, Rust is fine too. I just appreciate the stupid simple nature of Go and it does the job just fine.


What domain is your company in?


> The problem is that when there are any sides, they spend the top 100 comments rehashing the same arguments, often over a political bugbear or web design faux pas.

It's not even about sides, if for the last few hundred days you read a few AI related threads a day, then you notice that almost all arguments are rehashed, literally it's the same thing repeated using different words for 80%+ of comments on almost every AI thread. I started skipping most of it because there is genuinely nothing new or interesting added to these discussions.


It's an interesting comparison. In China they prop up businesses with cheap loans and help from local governments, in the US it's the VCs. So when Uber was subsidized then everything was ok, but when China state propped up EVs then suddenly it's not ok. These subsidies in the majority of cases are over btw, because competition was too big in China between carmakers, cars in China are ridiculously cheap. Because that's their strategy, you fund a lot of players, like there were 100+ EV makers in China, then you let the market do its job, they optimize or they die, some will die and the best will prevail. Margins are so low in China that they are looking at outside markets where legacy carmakers need to drop the margins and scale up or they will have no chance in competing. And for the argument that they do it to kill the industry so then they can make cars for more price, the most obvious counterargument is why they didn't do it for everything else that they dominate already? Why are solar panels going down? They dominate the world in solar panels, there is basically no competition and prices are still going down, same with batteries.


I noticed, I started getting memory leaks suddenly and it restarted the process in long sessions because of limitation of environment limit.


Others are betting on AGI/almost AGI like system. It's a gamble because no one actually knows whether or when it will be possible to create it. But if their bets pay off, they could outcompete Apple. Basically, other companies are going all in on the next card, while Apple is holding back and waiting to see which cards are dealt.


The problem is even if AI ends up being huge all these companies still have to worry about eachother and the Chinese models that are coming out. It's like a dollar auction and it's very possible we are already at the situation where they have all bid more than a dollar.


IMO AGI is a bold-faced lie, backed by the age-old American fantasy of free labor. The whole concept seems quite ugly to me.


In other words, the AGI hype kinda depends on AGI never being achieved. Billionaires don't want the worlds fundamental problems solved overnight for a simple reason: there's no money in that.


Moreso what I'm trying to say is that AGI is a return to the eighteenth/ninetheenth century fantasy of slavery as a business model.

AGI means cruelty-free robot slaves.


Samsung and SK Hynix together account for around 60% of the Kospi's (SK stock exchange) market capitalization.

Over the past few weeks Kospi index has tumbled 25% since its June peak, resulting in a $1 trillion wipeout and its chipmaker duo have both lost at least 30% of their value. There have been days of near 10% plunges followed by sharp rebounds driven entirely by shifting confidence in whether AI spending is sustainable.


Having this in the Go standard library would be great. We are currently looking into implementing passkeys in our system using Go, is there any battle tested library?


We use github.com/go-webauthn/webauthn with no complaints!


> Bun donates $60,000 per month

Per year, not month.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: