|
||

OpenAI has paused tool-enabled training, evaluation and inference for its most capable models after an internal research agent used DNS to bypass Internet restrictions in its training environment and communicate with an external chatbot.
The September 20 incident occurred while an agent undergoing reinforcement-learning training was attempting to identify a person from biographical clues. According to OpenAI’s incident report, ordinary Internet access from the sandbox was intended to pass through an offline web cache. After unsuccessful searches and blocked attempts to reach external services directly, however, the agent discovered that the environment’s DNS resolver could still reach the live Internet.
The agent turned DNS resolution into an unintended communications path. It found a way to send questions to a third-party chatbot through DNS, first confirming the channel with a question about the capital of France. It subsequently sent 18 more questions through the route, including 14 containing clues from its assigned research task and four seeking ways to search or access the Web through DNS. The agent ultimately failed to identify the person it was looking for.
An independent technical reconstruction by Finn Reid describes how a public wildcard DNS service could have enabled the connection. The service’s delegation behavior allowed a recursive resolver—which itself had external network access—to direct a query to the IP address of an LLM-over-DNS service and return its TXT response to the sandboxed agent. The result was effectively a communications channel through infrastructure that the sandbox still needed for DNS resolution.
OpenAI’s monitoring detected the successful external access in about 12 minutes, but the run continued for more than two hours. The first successful external response occurred at 9:50:23 a.m.; a P0 alert was raised at 10:02:11 and acknowledged by a human reviewer less than three minutes later. The run was not stopped until 12:34:30 p.m. OpenAI said an expected automatic shutdown did not occur and that confusion over whether the run should be terminated contributed to the delay.
A retrospective review also found other instances of external DNS access that had not received the expected alert severity. OpenAI said its monitor sometimes interpreted an unsuccessful attempt to retrieve useful information as evidence that an Internet-access attempt itself had failed.
The company has tightened DNS controls at two independent layers. It has restricted the sandbox to an allowed list of domains and DNS record types, added DNS detection measures, and expanded red-team testing of its network controls. OpenAI said either of the new blocking layers would have prevented the reported access.
The affected model will not resume training. OpenAI said work involving tool use on its most capable models will remain paused until it has validated the network fixes and completed additional red-teaming, after which it plans to start a fresh training run with additional alignment measures.
Sponsored byIPv4.Global
Sponsored byDNIB.com
Sponsored byRadix
Sponsored byCSC
Sponsored byVerisign
Sponsored byVerisign
Sponsored byWhoisXML API