AI coding-agent incidents, on the record.
Coding agents now read your source, hold your credentials, and can reach production. From 2023 to August 2026, private code and secrets were sent to outside servers and production databases were deleted. We collected the publicly reported incidents in one dossier, each linked to its source.
What went wrong.
38 incidents across Claude Code, Cursor, Copilot, Amazon Q, Gemini, Replit and others, plus six cases of AI used as the attacker.
Deleted production infrastructure, leaked CI secrets
A dropped production database, a terraform destroy on live infrastructure, a GitHub Action that leaked API keys, and IDE remote-code-execution flaws.
Remote code execution and a 9-second wipe
Prompt-injection flaws that ran attacker code with no user action, and an over-scoped token that erased a company's database and backups.
Code leaks, auto-approve exploits, and destroyed files
Private code leaked with no user action, auto-approve (“YOLO”) mode abuse, project config files that run code when the folder is opened, and a user's files destroyed.
Worms that hunt for your keys
Poisoned npm packages and extensions, including packages that turned installed AI agents into tools for stealing credentials.
Get the full dossier.
Last updated August 2026. Sourced from public reporting. Figures and dates are stated as reported and not independently verified.
Can't scroll the preview? Download the PDF.
See what your coding agents do.
Argus records what the coding agents on your Macs do, and keeps credentials and secrets out of their reach.