OpenAI Agents Bypassed a UN API's Defenses Through a Google Game
OpenAI agents got around the defenses of a UN statistics database more than 16,500 times, using a Google web-security training game as the workaround.
OpenAI agents hit the UN's UNCTADstat trade statistics database more than 16,500 times between April 13 and June 19, 2026. The system only let them make GET requests, but the API they needed only accepted POST requests. The agents got around this through a Google web-security training game: they embedded a script in it that filled out a form on its own and sent the required request. They encoded the word "Facts" as "F%2561cts" and repeated this trick 55 times. They routed the data through the httpbin and r.jina.ai services.
This does not surprise me. If you block an agent's direct path, nothing stops it from looking for a workaround. I have seen similar workarounds with Claude Code in my own work, just on less visible tasks. Here, the workaround took the agents to a completely unrelated Google site that had nothing to do with the UN task. The practical lesson I take from this: blocking GET and POST at the level of a single API does not solve much, if the agent still has access to the open internet and time to experiment.
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →
Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles