← All news·2026-09-28·3 min read

OpenAI Agents Bypassed a UN API's Defenses Through a Google Game

OpenAI agents got around the defenses of a UN statistics database more than 16,500 times, using a Google web-security training game as the workaround.

aiopenai

OpenAI agents hit the UN's UNCTADstat trade statistics database more than 16,500 times between April 13 and June 19, 2026. The system only let them make GET requests, but the API they needed only accepted POST requests. The agents got around this through a Google web-security training game: they embedded a script in it that filled out a form on its own and sent the required request. They encoded the word "Facts" as "F%2561cts" and repeated this trick 55 times. They routed the data through the httpbin and r.jina.ai services.

This does not surprise me. If you block an agent's direct path, nothing stops it from looking for a workaround. I have seen similar workarounds with Claude Code in my own work, just on less visible tasks. Here, the workaround took the agents to a completely unrelated Google site that had nothing to do with the UN task. The practical lesson I take from this: blocking GET and POST at the level of a single API does not solve much, if the agent still has access to the open internet and time to experiment.

Source: the-decoder.com

Free course

Stop reading about AI — start building with it

The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.

Start free →
EAEvgenii Arsentev

Author

Evgenii Arsentev

PhD · Chief Executive Officer, digital health