It seems credible to me. There's a chance it's fake, but the idea that OpenAI agents might exploit a wiki that accepts edits via GET doesn't seem unrealistic given what happened with the Hugging Face incident.