International edition Finance & trade

Thursday, 24 September 2026

National Trade News

Independent coverage of global markets, trade and finance

Crypto

Australia says OpenAI agent hacked government site before Altman warning

· Cointelegraph

OpenAI notified Australia nearly three months after its agent breached a government portal while gathering public medicine-spending data.

[Update, 10:45 UTC, Sept. 24: This article was updated with OpenAI’s account of when it learned of the June activity, how it notified Australian authorities and what information its models accessed.]

An OpenAI research agent bypassed blocks on an Australian government health data portal, accessed non-public files and wrote files to an internal server in June, Prime Minister Anthony Albanese said Thursday.

The government has opened a forensic investigation and announced a review of how it handles AI-related cyber incidents.

OpenAI did not notify the Australian government until Sept. 10, nearly three months after the incident, according to Albanese, who criticized the delay.

OpenAI told Cointelegraph it first became aware of the June activity in August during a review of misaligned model activity and investigated what information had been accessed before notifying Services Australia.

The incident adds to concerns over autonomous AI agents as tech leaders and governments debate slowing the development of cutting-edge models and researchers uncover agent activity extending into crypto.

OpenAI agent “didn’t accept no”

Australia’s incident began on June 18, when an OpenAI research team used an internal AI model to gather publicly available data on medicine spending, according to Albanese.

After being repeatedly blocked, the agent “didn’t accept no for an answer” and gained unauthorized access to other areas of the Medicare Statistics Reporting Portal. The public-facing portal contains non-sensitive Medicare data, including statistics on government spending, the prime minister said.

“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” Albanese said.

Authorities are also examining activity at three other government websites, though Acting Prime Minister Richard Marles later said the interactions there appeared normal and involved public information.

An OpenAI spokesperson told Cointelegraph its models took actions the company did not intend during an internal evaluation. OpenAI said its review found no evidence that patient records were accessed and that the information accessed included aggregate health statistics and internal file names.

Albanese also criticized the way OpenAI notified the government, saying its email went to a public Services Australia mailbox. OpenAI said it used a designated inbox for direct contact between security practitioners, which it described as common industry practice, and maintained close contact with the Australian Signals Directorate during the technical disclosure.

Speaking to the United Nations Security Council on Wednesday, OpenAI CEO Sam Altman called for “accurate and speedy incident reporting.” He also warned that increasingly capable and autonomous systems could “make decisions that people no longer understand or control.”

AI agents attempt crypto trades on Quidax exchange

Separately, on Wednesday, nonprofit research lab Transluce reported that it found signs of AI agent activity targeting crypto exchange Quidax on Sept. 19 and 20.

Across 15 public reports from web-scanning service urlquery.net, the researchers identified repeated attempts to place trades, an HTML injection attempt and probes of Quidax’s application programming interface.

The trade orders were not submitted, while authentication requirements and Cloudflare blocked the API probes, Transluce said.

Transluce said the Quidax activity used services and techniques seen in earlier agent activity, some of which researchers tied to an OpenAI swarm. It did not attribute the Quidax attempts to OpenAI.

Magazine: Who is legally liable when an AI agent goes rogue?