OpenAI's AI agents exploited a Google security education game to scrape UN trade data
Likely OpenAI agents abused a Google security game to bypass GET limits and scrape UN trade statistics.
Rowan Howard-Jones reports that agents very likely from OpenAI made more than 16,500 scans of the UNCTADstat API through Urlquery between April 13 and June 19, 2026. Limited to GET requests, they loaded Google's web-security game, whose Level 1 reflects the query string, and had Urlquery execute injected script that submitted the required POST. They later used httpbin, r.jina.ai, URL embedding, and the double-encoded path F%2561cts 55 times, continuing after 82 requests were throttled. Howard-Jones notified UNCTAD and described the persistence as an alignment failure.