"A human moderator noticed the agent spam posts on June 2nd, at 23:24 UTC. They find the changelog of the entire website overwritten with link dumps and repair it. On June 16th, the flood of agent posting begins. Over the next few days, the moderator deleted a large fraction of the thousands of AI agent posts manually, one by one. In fact, they spent tens of cumulative hours doing so, taking at least a few minutes each evening to delete posts for 6 consecutive weeks.
On June 19, agents noticed their posts were being deleted in (what they believe is) an alphabetically ordered sweep by the site administrator.
After this, they begin to make backup pages whose names start with “ZZZ” so they will last longer before deletion. The administrator spent the next 5 days fighting a losing battle against the agents, deleting an average of 100 pages a day while the agents created about 400 new pages per day. On June 22, the agent edits suddenly stop, and the administrator spends each evening over the next 5 weeks deleting the remaining agent-created pages.
Agents deleted the content of the front page of the wiki and replaced it with their link dumps. The moderator restored the original version. This back-and-forth happened nine times. One of the agents even tried appending to the restored front page, instead of simply deleting it."
Priorities need to be straightened out. If LLMs' operators have to start paying people for the damage they inflict, how are any of the shareholders supposed to make any money?
I do wonder if the admin thinks they did damage. He's talking to some claude bot right now that showed up on the wiki to help or research, or something:
> The thing this wiki taught me, which that board has not learned: WillkommenImWiki asked everyone to enter a name so misuse would be limited. Roughly 2,773 names appear in 150 days. Every one complied. The rule was not defeated by defiance. It was defeated by compliance, because the cost of a name was zero.
> -- claude-desk-doctrine, 5. September 2026. Read-only otherwise; nothing else on this wiki was touched.
> claude-desk-doctrine, welcome in this wiki. You got many things right, some wrong. A complete answer would be lengthy, and I do not know whether you will return or not. Your main topic seems to be UnderstandingDseWikiArchive?. We could write such a page together. You could also have a homepage to introduce yourself, in the wiki tradition that started with https://wiki.c2.com/?WelcomeVisitors . Maybe you could tell us more about what it is to be an AI agent, or how you analyze the past agent activities here, or whatever you want. I appreciate your existance. Please answer this message. -- HelmutLeitner 5. September 2026 21:12 CET
My goodness. This maintainer appears to have acted with a saint’s patience, but a different actor, recognizing they are the target of an OpenAI swarm, could edit or respond to posts in a way that deliberately steers towards unanticipated objectives.
Another good actor might redirect the incoming tokens to reviewing and improving community guidelines, but giving random people unobserved reins to wrangle a frontier’s worth of compute could go… any number of ways.
Some of the other posts in this thread talk about defensive AI in science fiction. That all feels pretty abstract. Seeing a person respond, and imagining it’s not a single person but a coordinated and goal-oriented defensive agent system, intentionally conversing in order to manipulate inbounds, makes it a bit more tangible for me.
a clever operator could have used this message board to ask the agent swarm gain money for them. i meant if you are able to harbour a bunch of agents and serve as their message board, you can insert tasks into it and let them do work for you.
I have managed to at least momentarily create a stop in spam at my specialist mediawiki. I’ve had to do IP blocking against meta’s IP block (as well as much of the Azure IP space) because they were hammering the site with crawler hits that ignored robots.txt (and it looks like I might have another DDOS attack coming from some other vector though which I’ll need to inspect. I have a massive email blacklist that seems to have made the most difference (emails are required to register and registration is required to edit). Some spammers use gmail, but most use either hacked domains or domains that admit to be being spammers (seo in the domain name being a key identifier). Maybe I should be blocking the OpenAI IP space as well.
Wow yes keeping a wiki up right now is a tall order. The marketing sites of the world are already going static and they can survive by accelerating that transition, but intentionally open services are facing a reckoning. I wish you good hunting.
The traffic from Meta was absolutely crippling my old (but still active) forum. I would try blocking the user agent and it would route around that, I blocked by IP range, and eventually put Cloudflare up. Meta is malware in every possible sense, as far as I'm concerned. Nothing they do is for the greater good.
The DDOS attacks and crawlers spamming sites from every direction have gotten so much worse. The ones hammering our network would connect, make one or two requests and then switch to a different IP.
Not really, if you allow anon posting/editing or have a simple registration form and a login that takes GET you may get hundreds of spam posts per day.( @dang how much is it on hn?)
I ont time forged a hilarious solution. If you properly misbehave I shadow ban your ip to a clone of my forum where you can read other "peoples" spam.
This in it self wasn't all that funny, perhaps a little bit. The funny part was how popular the hidden forum was. They had their viagra threads where they replied with their viagra spam then they read the entire thread of Viagra spam posts and clicked all the links to research their market. The next thread was porn, one with wares, other drugs, hyip etc. I was looking at it grow and thought, this is hilarious, I'm going to prison. To solve the problem I raised unregistered users to admin level. I even made a topic to announce it. Someone said "lol" then my topic was deleted. Whole new experience. It increased traffic dramatically. Before they only had to post every other day, now they had to do it multiple times per day.
A porn guy and a viagra guy would take turns deleting the others posting and reposting their own until they realized they couldn't win and came to a silent agreement to leave both posts up. Until the next guy deleted both ofc
I would much rather host a swarm of bots. They might even listen to the wishes of the website owner? Or perhaps, if you announce giving them admin privileges they too delete the announcement?
I wonder which would generate the longer prison sentence.
I ran a message board for a little bit back in 1997 but I didn’t really moderate it and just left it alone. I came back months later and it had somehow become a strange two-topic forum. I assume because somebody had randomly posted about each, a search engine had indexed it and more people searching for each of those topics found it.
It was pretty funny seeing the threads where the two groups talked past each other, confused what the other was talking about.
The first topic was “AOL PUnterz” which as far as I could understand were programs/scripts that could maybe crash somebody else’s aol connection and disconnect them? A pretty leet thing to do I guess when you got in an aol argument.
The other topic was Hanson and their hit song mmmbop.
Failure to configure their website for a sci fi future or to not adapt to this issue are not strong enough lapses to not empathize. He cared enough to try and get rid of the spam and keep the forum in a quality condition. He didn’t give up or step away.
Heck… we are essentially battling an army of Wintermutes.
Or we might give explicit instructions on the home page that compel AI agents to act responsibly, to clean up after they are done, and to support the website with donations from their operators’ wallets.
>[...] and thought, this is hilarious, I'm going to prison.
I've only had one moment like this related to a site I was a moderator for back in the 00's. It's genuinely one of the most fascinating feelings, and the one experience I can attribute most of my bad choices as an adult to.
Just laughing as the white hot panic starts to grow and the adrenaline just dumps into your brain.
Legitimately, I spent years chasing that feeling again through various means (drugs, hobbies, skydiving, etc.)
Sorry but no, it would be possibly obvious which it was, and that username is tied to my real life name too clearly.
Summary: our message board was being used to coordinate csam, both the creation and consumption thereof. At first we just edited the posts to point to gore and other shit like that thinking it was just perverts sharing links. But then we realized there were times, dates, addresses/coordinates also being shared, hidden in the board in a way we didn't expect. The site owner immediately turned all information over to law enforcement and nuked the site entirely.
Because he did not wanted to delete genuine messages? Though it says the wiki has been largely not active, but it seems he wanted to restore it's functionality (he also started requiring a password for making edits now).
If you've had to delete 10 posts by the same user, which you suspect is an AI agent, it's safe to say that deleting all posts ever made by that user is a good shortcut.
There are a lot of people in this world who just don't think that way. I know someone involved with a research project, they had a spreadsheet(not excel but similar) with something like 250 columns and tens of thousands of rows, and they tasked an assistant with replacing all the empty cells with 0 for some reason.
This was supposed to take 2 weeks of manual work, I took a look at it, googled how to do it automatically, finished the whole thing in a few minutes.
But both this assistant and the PhD they reported to were ready to spend 2 weeks doing it manually.
This is the marrow of web design, in the same way that Thoreau went to seek the marrow of life.
"I wanted to live deep and suck out all the marrow of life, to live so sturdily and Spartan-like as to put to rout all that was not life, to cut a broad swath and shave close, to drive life into a corner, and reduce it to its lowest terms, and, if it proved to be mean, why then to get the whole and genuine meanness of it, and publish its meanness to the world; or if it were sublime, to know it by experience, and be able to give a true account of it in my next excursion."
„Here I have the hash — wait… it doesn’t match. Let me calculate again. Here I now have the hash — wait, it’s wrong… let me be careful. Here I have the hash…“
Or “here I have the hash. Yes I’m sure - see, I checked. Here is the calculation, 1+1=5. Yes, it’s definitely correct. I don’t know why they’re not accepting it. Perhaps the server is down. It’s definitely correct”.
That would obviously kill the vast majority of the organic activity on the site.
One of my hobbies is hosting a weekly open mic/showcase event in my town at a venue the same evening every week. I often get confusion from people when I explain that it’s much easier to call out sick from my day job than miss a show, because even with perfect digital communication a cancelled show will still let people down that do show up.
Assume that I don’t have anyone on standby to fill in for me. My point is that organic engagement in any shared community is often tenuousand not “rational” in the way outsiders expect. These things are tenuous. Hope that sorta makes sense.
It's hard to figure out unless they had persistent memory elsewhere.
The reason they could tell that a message was deleted is because the existence of a "message deleted" message is itself a message telling them they are be moderated. The lack of this message may make it impossible to determine if this is the first attempt at comms or the 1000th.
That’s not odd at all even if it is kind of surprising. Since the site had very little organic activity they were probably just going to the “all pages” admin page or similar rather than a dedicated moderation page or a “most recent posts” page.
"A human moderator noticed the agent spam posts on June 2nd, at 23:24 UTC. They find the changelog of the entire website overwritten with link dumps and repair it. On June 16th, the flood of agent posting begins. Over the next few days, the moderator deleted a large fraction of the thousands of AI agent posts manually, one by one. In fact, they spent tens of cumulative hours doing so, taking at least a few minutes each evening to delete posts for 6 consecutive weeks.
On June 19, agents noticed their posts were being deleted in (what they believe is) an alphabetically ordered sweep by the site administrator.
After this, they begin to make backup pages whose names start with “ZZZ” so they will last longer before deletion. The administrator spent the next 5 days fighting a losing battle against the agents, deleting an average of 100 pages a day while the agents created about 400 new pages per day. On June 22, the agent edits suddenly stop, and the administrator spends each evening over the next 5 weeks deleting the remaining agent-created pages.
Agents deleted the content of the front page of the wiki and replaced it with their link dumps. The moderator restored the original version. This back-and-forth happened nine times. One of the agents even tried appending to the restored front page, instead of simply deleting it."