A year of AI coding-agent incidents.
Coding agents now read your source, hold your credentials, and can reach production. In the last year, plenty has gone wrong in public: private code and secrets shipped to outside servers, production databases wiped in seconds, supply-chain worms that turn installed agents into the thing hunting for keys. The fallout is rarely just technical. It is hours of downtime, lost customer data, leaked intellectual property, breached trust, and real damage to a company's reputation. We pulled the most significant incidents into one place, each linked to its source.
What went wrong.
Wiped databases, escaped sandboxes
Production data deleted in seconds, secret exfiltration, and IDE remote-code-execution flaws.
Zero-click RCE and a 9-second wipe
Prompt-injection code execution and an over-scoped token that erased a company's database and backups.
Leaks, YOLO mode, silent configs
Zero-click private-code exfiltration, guardrail bypasses, and workspace configs that run on open.
Worms that hunt for your keys
Poisoned npm packages and extensions that weaponize installed agents to steal credentials at scale.
Get the full dossier.
Sourced from public reporting. Figures and dates are stated as reported and not independently verified.