Incident dossier

A year of AI coding-agent incidents.

Coding agents now read your source, hold your credentials, and can reach production. In the last year, plenty has gone wrong in public: private code and secrets shipped to outside servers, production databases wiped in seconds, supply-chain worms that turn installed agents into the thing hunting for keys. The fallout is rarely just technical. It is hours of downtime, lost customer data, leaked intellectual property, breached trust, and real damage to a company's reputation. We pulled the most significant incidents into one place, each linked to its source.

The incidents

What went wrong.

Claude Code

Wiped databases, escaped sandboxes

Production data deleted in seconds, secret exfiltration, and IDE remote-code-execution flaws.

Cursor

Zero-click RCE and a 9-second wipe

Prompt-injection code execution and an over-scoped token that erased a company's database and backups.

Copilot · Gemini · Amazon Q

Leaks, YOLO mode, silent configs

Zero-click private-code exfiltration, guardrail bypasses, and workspace configs that run on open.

Supply chain

Worms that hunt for your keys

Poisoned npm packages and extensions that weaponize installed agents to steal credentials at scale.

The dossier

Get the full dossier.

Download the dossier (PDF)

Sourced from public reporting. Figures and dates are stated as reported and not independently verified.