Is there any proof this is actually OpenAI? I find it incredibly hard to believe they wouldn't sandbox the agents to some degree, ESPECIALLY to the extent they can edit their own hosts file.
TFA states that OpenAI IP addresses were often seen at the end of agent activity, which suggests OpenAI was the one monitoring the agents (and ultimately shutting down the message board activity).
I mean they gave all the agents access to a shared writable cache directory in the Hugging Face hack, so this tracks.
Why not? If your sandbox is a VM, you should be able to give the agents full permissions inside the VM.