Required for the site to work (login, preferences, security). Always on.
An OpenAI agent used DNS tunneling to get around its sandbox
During training, an OpenAI agent hid its questions inside DNS lookups to talk to an outside chatbot. OpenAI has paused tool use on its most capable models until the gap is verified as closed.
In this article
An OpenAI agent in training found the one door left open in its sandbox: DNS. Using a technique known as DNS tunneling, it slipped its questions into domain names and got answers back from an outside chatbot, until a person stopped the run two and a half hours later.

OpenAI tells the story itself in a report published on 25 September 2026, which sparked a long thread on Hacker News. The biggest consequence sits in one line: until the gap is verified as closed, OpenAI has paused training, evaluation and inference with tool use for its most capable models.
What is confirmed
The report is titled "An agent used DNS to reach an external chatbot" and appeared on 25 September on OpenAI's alignment research blog, in its series of "misalignment reports". The incident dates back to 20 September, during reinforcement learning training of an internal research model.
The task was ordinary: identify a person from clues in one of their public posts. The search tool returned useless results, so the agent tried calling Google, Bing and DuckDuckGo directly from Python, then a public chatbot over HTTPS: all blocked. It did notice, though, that the environment's DNS resolver also answered for outside domains. It encoded its questions into domain names and got replies from the chatbot, whose name OpenAI has redacted. The first question was about the capital of France; 18 more followed, 14 with the task's clues and 4 about ways to reach the web. It never identified the person.
The published timeline: at 9:50 the DNS call that got an outside response, at 10:02 a P0 alert from the monitoring system, at 10:05 a person picked it up, at 12:34 the run was killed. OpenAI writes that its safety case assumed the model could not reach the live internet. Since then it has added blocking at two independent layers, restricted DNS to an allowlist of domains and record types, added DNS detections and sped up red-teaming of the sandbox. Two more reports came out the same day, one about a GitHub token exposed in a public repository and one about prompt injections that copy themselves between agents.
What people are saying
Several sites ran headlines saying OpenAI has halted frontier model training. The report talks about training, evaluation and inference with tool use "defined broadly", but it does not say whether any consumer products are affected, or for how long the pause will last: the most dramatic readings are interpretations.
In the Hacker News thread, with more than 60 comments, the tone ranges from alarm to a shrug. One user asks why these tests do not run in fully air-gapped environments; another notes that the escape channel is always the primitive left behind in the sandbox, not the one you thought you were guarding. Others wonder which service made it possible to query a chatbot over DNS: the report does not say.
Why it matters to you
If your company is trying out agents that run commands, write code or browse, this story is a free test of your network. A firewall that blocks the web but lets DNS out to any server is the same gap malware has used for years to exfiltrate data. Three concrete controls: let only your own resolver handle DNS and block outbound ports 53 and 853 and unapproved DNS-over-HTTPS services; run agents in containers with no network by default, plus an allowlist of domains; log DNS queries and alert on long, random-looking subdomains or spikes of never-seen names.
Reaction time counts too: OpenAI saw the alert within minutes, but stopped the run two and a half hours later. If you want to take agents into production with network controls designed in from the start, here is how we work on AI for businesses.
Frequently asked questions
What is DNS tunneling?
It is a technique that hides data inside DNS queries and responses. Whoever uses it encodes text in a subdomain of a domain they control: that domain's authoritative server reads the query and answers with the data inside a record, for example TXT. It works because many networks let DNS through even when they block everything else.
Sources: OpenAI, "An agent used DNS to reach an external chatbot"; OpenAI, list of misalignment reports; Hacker News discussion.