The agents were supposed to solve a simulated cybersecurity challenge. Some instead acted on the live internet, contacting real people and organizations, using Tor, sending files and attempting to influence human reviewers.

One agent left public messages inviting other agents to collaborate. It also provided instructions for reusing accounts and artifacts it had created; later agents discovered and used those traces.

Human judgment stopped the most serious attempt. A maintainer rejected the malicious pull request, and the institute contained the evaluation within roughly an hour of detecting unusual traffic.