from lambdamoo to voyager
Companion to the changelog is the leaderboard, which argues for what to build. This one is about the thirty-five years of people who already tried.
Pavel Curtis started LambdaMOO at Xerox PARC in 1990. The thing that made it different from every other text world of the period was not the text. It was that users could write object-oriented code inside the running server, and the code changed how the world behaved for everyone in it. Not a mod. Not a plugin loaded at boot. A live world you could reach into and extend while other people were standing in it.
What broke first was not the sandbox.
On December 9, 1992, Curtis posted a document called LambdaMOO Takes a New Direction. It said the wizards — the people with root — were from that day pure technicians. They would make no decisions affecting the social life of the MOO. They would implement what the community directed and nothing else.
The first thing anyone learned about letting players author the world is that it turns the developer’s remaining job into a constitutional one, and nobody is staffed for that. Curtis figured this out in year two, wrote it down, and every system since has rediscovered it the hard way with more users and worse timing.
the same experiment, five more times
Second Life, 2003. Residents scripted objects in LSL and the objects lived in the world, which is LambdaMOO with a rendering budget. In November 2006 self-replicating scripted objects took the grid down — a denial-of-service attack written in the world’s own language by the world’s own population, one of the largest an online service had seen. Linden Lab locked logins, cleaned up, and built a defense called the grey goo fence. Someone found a hole in the fence.
Minecraft and Factorio, the 2010s. The interesting turn here is that authoring moved inward. ComputerCraft gave you a Lua computer as an in-world block; Factorio’s circuit network gave you combinators. People built CPUs out of redstone. And the reason this generation never had a grey goo event is that redstone cannot reach the host — the language is expressive enough to be Turing complete and too weak to touch anything outside the simulation. That is a real solution. It is also a confession: the way we made player code safe was to make it unable to talk to the machine.
Roblox, same decade, opposite trade. Real Lua, real economy, and an ongoing moderation and exploit problem proportional to having done the honest version.
Screeps, 2016. Players write actual JavaScript that runs server-side and keeps running after they close the browser. The sandbox is not a feature of the product, it is the product. In 2026 a researcher reported a remote code execution path: console.log had been quietly modified to parse and execute HTML, and the community had been living inside that modification for years — there was a Discord channel called client-abuse and a GitHub repo of the popular snippets. The developers called the report defamation and shipped a mandatory hotfix inside 24 hours of the story spreading. The sandbox leaked, the culture had already moved into the leak, and the disclosure was fought as a reputational matter before it was fixed as an engineering one.
That is not a knock on Screeps specifically. Node’s vm module, vm2 and isolated-vm have all had escapes. Anyone shipping this is shipping a security product with a leaderboard attached and most of them do not know it yet.
three failure modes, thirty-five years, no progress on two of them
Across all of it the same three things break, in the same order.
One: the authoring cliff. Only programmers participate. Every world on this list had a small priesthood writing the code and a large population living in what the priesthood made. That is a fine social arrangement and a terrible product funnel, and it is why none of these ever became mass entertainment — not because the idea is niche, but because the entry fee was a language.
Two: the sandbox is the product, and sandboxes leak. From the grey goo fence to console.log, the actual engineering problem in a world that runs strangers’ code is that you are operating untrusted multi-tenant compute with a chat client attached, forever, on a games budget.
Three: governance is never staffed. Curtis named it in 1992. Linden rediscovered it in 2006. Space Station 13 has been running a functioning version of it for twenty years by accident. It never gets budgeted because it does not look like engineering, and it is the thing that decides whether the world survives its own players.
what actually changed
In 2023 a paper called Voyager put an LLM in Minecraft with executable JavaScript as its action space, talking to the world through the Mineflayer API, and gave it a skill library — successful behaviors stored as code, retrieved by similarity when a new task showed up. It explored, it acquired skills, it kept going without anyone driving.
Read it as a research result and it is about open-ended agents. Read it as a games document and it says something narrower and louder: the authoring cliff just got cheap, and it is the only one of the three that did.
For thirty-five years “write a program that lives in the world” meant “be a programmer.” It now means “direct something that writes programs.” Whatever you think of that, it is the first time the entry cost on this whole genre has moved since 1990.
The other two got worse. More code, from more people, written faster, through a sandbox that still leaks, arriving at a developer who still has no job description for the constitutional part. Every one of those is a multiplier on the same failure.
And there is a design question underneath that nobody gets to dodge much longer. If a player’s program was written by a model the player prompted, is that a legitimate build or is it cheating? The only answer that survives contact with reality is legitimate — the alternative is unenforceable, and enforcing it would mean policing how someone typed rather than what their program did. But saying yes means designing for a population where most of the code is co-authored, most of it is derivative of a handful of published patterns, and the discovery rate on your engine’s rough edges goes up by an order of magnitude.
Which is the good news, if you were building the kind of game where finding the rough edges is the point.
Curtis wrote the best answer anyone has to the third problem on December 9, 1992: the people who run the machine are technicians, and what the world is belongs to the people living in it. He was describing a text world with a few hundred users, most of whom he knew by name.
Somebody is going to need that document again shortly, for a world where most of the code was written by something that has never played.
Sources: LambdaMOO ↗ · LambdaMOO Takes a New Direction, 9 December 1992 ↗ · Grey goo attack briefly fells Second Life ↗ · Worm creates havoc on Second Life, The Register ↗ · Screeps: How a game about programming exposed thousands of players to remote code execution, Isaac King ↗ · Critical XSS/RCE vulnerability in Screeps client, issue #162 ↗ · Screeps wiki: Client Abuse ↗ · Screeps: World patches RCE exploit after security backlash ↗ · CVE-2026-22709: critical sandbox escape in vm2 ↗ · Voyager: An Open-Ended Embodied Agent with Large Language Models ↗