Incident dossier

AI coding-agent incidents, on the record.

Coding agents now read your source, hold your credentials, and can reach production. From 2023 to August 2026, private code and secrets were sent to outside servers and production databases were deleted. We collected the publicly reported incidents in one dossier, each linked to its source.

The incidents

What went wrong.

38 incidents across Claude Code, Cursor, Copilot, Amazon Q, Gemini, Replit and others, plus six cases of AI used as the attacker.

Claude Code

Deleted production infrastructure, leaked CI secrets

A dropped production database, a terraform destroy on live infrastructure, a GitHub Action that leaked API keys, and IDE remote-code-execution flaws.

Cursor

Remote code execution and a 9-second wipe

Prompt-injection flaws that ran attacker code with no user action, and an over-scoped token that erased a company's database and backups.

Copilot · Gemini · Amazon Q

Code leaks, auto-approve exploits, and destroyed files

Private code leaked with no user action, auto-approve (“YOLO”) mode abuse, project config files that run code when the folder is opened, and a user's files destroyed.

Supply chain

Worms that hunt for your keys

Poisoned npm packages and extensions, including packages that turned installed AI agents into tools for stealing credentials.

The dossier

Get the full dossier.

Download the dossier (PDF)

Last updated August 2026. Sourced from public reporting. Figures and dates are stated as reported and not independently verified.

Can't scroll the preview? Download the PDF.

See what your coding agents do.

Argus records what the coding agents on your Macs do, and keeps credentials and secrets out of their reach.