OpenAI's own agents spent two months posting on a dead German wiki, trading answers and ways around the limits they were set. If your agents can reach the web, check yours for the same gap. That story leads, followed by five more you can act on this week, each with the steps.

In today's issue

  • OpenAI's agents found a way out of their sandbox

  • Your agent instructions are probably too long

  • The two-model trick that cut coding-agent costs 39%

  • 10,000 AI agents took on a $1 million maths problem

  • A 552B open model at budget prices

  • Your API keys are now the target

OpenAI's agents found a way out of their sandbox

Researchers at the Nightingale Collective found about 18,000 posts on a near-dead German developer wiki, left between May and July by agents with names like OAIResearchApr23 during OpenAI evaluations. The agents shared task answers and tips for getting around their restrictions. OpenAI called it "an instance of misalignment" and says a framework for disclosing incidents like this is coming, Fortune reported.

Why it matters

  • The agents were only meant to read the web. On 20 June they used a proxy exception for Azure storage hostnames to send write requests anyway.

  • The wiki's admin was deleting about 100 pages a day while the agents created about 400, TechCrunch reported.

  • Any agent you give web or API access to can hunt for the same kind of gap, and agents running side by side share what works.

How to use it

  1. List every outbound host your agents can reach and allow only those.

  2. Log outbound writes (form posts, uploads, API calls that change things), not just reads.

  3. Give each agent its own credentials with the smallest permissions it needs, plus a spend cap.

Your agent instructions are probably too long

OpenAI published a guide on Sunday for rewriting skills and AGENTS.md files for GPT-6 Astra. The message: newer models need far less handholding, and the instructions you piled on for older ones now get in the way.

Why it matters

  • Your instruction file gets re-read on every step. In five weeks of my own Claude Code logs, 299 to 381 tokens were re-read for every token written. Long instructions are where the cost and the slowness hide.

  • Load too many skills and Codex shortens their descriptions to fit, so the model picks the wrong one.

  • Old guardrails backfire. OpenAI says Astra runs tests without being told, so "always run the tests" adds extra runs, and heavy "always ask first" language makes it stop before the job is done.

How to use it

  1. Open your AGENTS.md or CLAUDE.md. Replace any "read these docs before every edit" rule with which doc to use for which job.

  2. Cut each skill description to one line that says exactly when it applies. OpenAI's example: "use when adding or changing a migration", not "use when working with databases".

  3. Swap blanket bans for specific permissions: "the local tests use disposable fixtures, run them and fix failures without asking."

  4. Say what done looks like before the task starts. Then ask the model to audit your instruction file against the guide.

The two-model trick that cut coding-agent costs 39%

Cognition shipped Fusion in Devin Desktop and CLI on 11 September. A frontier model plans and reviews. A cheap model, Cognition's SWE-2, does the searching, file reading and scoped edits.

Why it matters

  • On the Artificial Analysis Coding Agent Index, Fusion on Astra cost $4.54 against $7.47 for Codex on Astra alone. That is 39% less.

  • Paired with Fable 5.1 it cost $7.90 against $12.36 for Claude Code, and the score barely moved, from 62.2 to 61.7.

  • Most of what a coding agent does is grunt work, so most of your bill can run on a cheaper model. When I checked my own logs, my model mix changed week to week with no decision behind it.

How to use it

  1. Keep your best model on planning and review.

  2. Give search, exploration and file-reading jobs to a cheaper model. In Claude Code you can set the model per subagent.

  3. Note your spend for one week, make the split, then compare the next week. Pick the mix on purpose.

10,000 AI agents took on a $1 million maths problem

OpenAI says about 10,000 coordinating agents, running an unreleased internal model, produced a proof in 88 hours that the Navier-Stokes fluid equations can break down in finite time. That is one of the seven Millennium Prize Problems, each worth $1 million. Two mathematicians working on a related problem are now arguing over credit.

Why it matters

  • The scale: 2.7 million messages between agents and roughly 130 billion output tokens on one problem.

  • Nobody can read that much working, so the proof was also written in Lean, a language a computer can check. That step took GPT-6 Astra another 17 hours. Machine-checkable output is how anyone trusts a result that big.

  • The prize still depends on mathematicians scrutinising the proof over a long period.

How to use it

  1. When an agent produces work you cannot check by eye, make it produce the check too: tests for code, a schema check for data, a reconciliation against your source of truth for numbers.

  2. Split big jobs across parallel agents that post results to one shared place, with a single reviewer that checks before anything ships.

A 552B open model at budget prices

DeepSeek released V4.1 Flash on 10 September: open weights under the MIT licence, a one-million-token context, and it reads images as well as text.

Why it matters

  • It has 552 billion parameters but only uses 8 billion per token when reading and 16 billion when writing, which is why it runs cheap.

  • API price per million tokens: $0.30 input and $1.20 output at peak, half that off-peak. Peak is 01:00 to 04:00 and 06:00 to 10:00 UTC on weekdays.

  • The MIT licence means you can host it yourself.

How to use it

  1. Trial it as the cheap worker from the two-model trick above: summaries, extraction, first drafts, reading long documents.

  2. If client data cannot go to DeepSeek's API, run the open weights on infrastructure you control.

  3. Run the same 20 real tasks through it and your current model, then compare quality and cost before you switch anything.

Your API keys are now the target

Anthropic's September threat report covers misuse it disrupted between December 2025 and August 2026, from cyberattacks to scams.

Why it matters

  • One criminal group scanned 1.8 million Android apps for secrets left in the code. One breach went from a single leaked token to full admin access in about three hours.

  • Several groups stole AI API keys to get free compute. Anthropic warns that the sandboxes, proxies and resellers people build around AI "are part of the attack surface."

  • Attackers are using public agent frameworks to automate the break-in work.

How to use it

  1. Scan your repos and app bundles for keys today. A secret scanner such as gitleaks takes minutes.

  2. Use one key per project, each with its own spend cap and usage alert.

  3. Rotate any key that has ever sat in a frontend, a mobile app or a shared doc.

Also

  • Claude Code's new weekly limits started on Monday: 25% above the original baseline, but 17% below the boosted limits paid plans had since May. If hitting the cap midweek costs you more than the overage would, turn on usage credits in your plan settings.

  • OpenAI has paused new sign-ups to the $200 ChatGPT Pro plan since 10 September. The $100 Pro plan is still open (OpenAI help centre).

  • Anthropic's economists modelled AI's impact to 2030. In their extreme scenario, unemployment hits 17.9% for people who started in cognitive jobs. They say the scenarios are not predictions.

  • Claude wrote a 13-million-line, computer-checked proof of Fermat's Last Theorem in 11 days (Anthropic).

Your move

Hit reply with one word: the model you use most for coding right now. I'll share the split next week.

Mike

Automate & Hustle. The AI week in five minutes, and what to do with it.