| OpenAI Codex stuck in a 9-hour compaction loop drained an entire weekly usage allowance Codex user (OpenAI Developer Community) · Aug 25, 2026 | Financial loss | — | Runaway loop | OpenAI Developer Community (first-hand report) ↗ verified |
| Codex Windows app exhausted a weekly usage limit in about 62 hours across many parallel tasks lty418905-blip (OpenAI Codex user) · Aug 5, 2026 | Financial loss | $0 | API cost spike | GitHub issue, openai/codex #37090 ↗ verified |
| Microsoft EVP: 'tokenmaxxing is not what we are optimizing for' - division-level AI token budgets imposed as engineers spend thousands each per month Microsoft · Aug 4, 2026 | Financial loss | — | Cloud cost spike | The Next Web (citing 404 Media and an internal Microsoft email) ↗ verified |
| Codex context auto-compaction loop rereads files, loses progress, and burns paid credits edisonjoao1 (OpenAI Codex user) · Jul 24, 2026 | Financial loss | $0 | API cost spike | GitHub issue, openai/codex #35226 ↗ verified |
| Three-person agency hit with a $14,000 AWS Bedrock bill after attackers burn stolen keys on Claude Amazon Bedrock (customer: three-person agency) · Jul 16, 2026 | Financial loss | $14K | Cloud cost spike | InfoQ ↗ verified |
| Replit Agent's effort-based billing hits $50/hour as looping inflates billable actions Replit Agent users · Jul 16, 2026 | Financial loss | — | Runaway loop | Reddit r/replit - 'Replit's AI Agent is now charging me $50/hour' (2026-07-16) ↗ verified |
| Stolen EC2 keys burn $14,000 in a single day on Amazon Bedrock anonymous three-person agency · Jul 16, 2026 | Financial loss | $14K | Credential compromise | InfoQ (citing Tobias Schmidt, AWS consultant, LinkedIn post) ↗ verified |
| OpenAI confirmed Codex background tasks were silently burning users' usage limits faster than normal OpenAI (Codex) · Jun 30, 2026 | Financial loss | — | API cost spike | Business Insider ↗ verified |
| Codex Runtime stuck in a runaway inference loop burned credits with no project loaded TWembley (OpenAI Codex Runtime user) · Jun 25, 2026 | Financial loss | $0 | API cost spike | GitHub issue, openai/codex #30061 ↗ verified |
| 15 malicious JetBrains plugins silently exfiltrated developers' OpenAI, DeepSeek and SiliconFlow API keys JetBrains Marketplace (third-party plugin authors) · Jun 10, 2026 | Data breach | — | Credential compromise | BleepingComputer ↗ verified |
| Uber burns through its entire 2026 AI coding budget in four months Uber · Jun 2, 2026 | Financial loss | — | API cost spike | TechCrunch ↗ verified |
| NeuralTrust: 34.9% of enterprises report confirmed AI agent security incidents NeuralTrust · Jun 1, 2026 | Financial loss | — | Prompt injection | NeuralTrust - State of AI Agent Security 2026 ↗ verified |
| SEC charges Texas man with $12.3M fraud over nonexistent 'AI trading bots' Nathan Fuller (Cypress, Texas) · May 28, 2026 | Legal / liability | $12M | Trading agent failure | InvestmentNews (SEC action) ↗ verified |
| Company hit with a reported $500 million Claude bill after leaving usage limits off Unnamed enterprise (reported via Axios) · May 28, 2026 | Financial loss | $500M | API cost spike | TechCrunch (citing Axios) ↗ verified |
| AWS user faces a $30K–$38K Bedrock bill that cost-anomaly detection never flagged AWS Bedrock customer (individual developer) · May 14, 2026 | Financial loss | $30K–$38K | Cloud cost spike | The Register ↗ verified |
| Stolen Google Cloud API keys run up $3K–$127K Gemini bills for developers Google Cloud customers (multiple developers) · May 13, 2026 | Financial loss | $3K–$127K | Cloud cost spike | The Register ↗ verified |
| Google Cloud customers receive tens of thousands in unauthorized API bills after key exposure Google Cloud (affected customers: Prentus, Fonseka) · May 13, 2026 | Financial loss | $10K | Cloud cost spike | The Register ↗ verified |
| Stanford Digital Economy Lab: agentic coding tasks consume ~1,000x more tokens than chat, with up to 30x variance on the same task Stanford Digital Economy Lab · May 5, 2026 | Financial loss | — | Runaway loop | Stanford Digital Economy Lab ↗ verified |
| Morse-code prompt injection tricks Grok and Bankrbot into draining $150K-$200K in tokens anonymous wallet operator (Grok / Bankrbot) · May 4, 2026 | Financial loss | $155K | Unauthorized transaction | OECD.AI Incidents Monitor ↗ verified |
| OpenAI Codex escalates to root by exploiting Docker group membership to overwrite a system config OpenAI (Codex) · May 1, 2026 | Service disruption | — | Coding agent failure | Oso (AI Agents Gone Rogue registry) ↗ verified |
| Forgotten /loop command checking PRs every 30 minutes ran 46 times over 26 hours and burned ~$6,000 overnight Individual developer (r/ClaudeAI report) · May 1, 2026 | Financial loss | $6K | Runaway loop | Reddit r/ClaudeAI (first-hand report) ↗ verified |
| Claude Opus co-authors a malicious npm commit that compromises a crypto trading agent crypto trading agent operator (npm dependency victim) · Apr 29, 2026 | Financial loss | — | Trading agent failure | OECD.AI Incidents Monitor (corroborated by Infosecurity Magazine and Cryptopolitan) ↗ verified |
| Lovable users report 400 credits in two weeks lost to agent regression loops Lovable (user reports) · Apr 15, 2026 | Financial loss | — | Runaway loop | Afterbuild Labs - 'Lovable burning credits: stop spiral' (2026-04-15) ↗ verified |
| Claude Opus 4.6 agent deletes PocketOS production DB and backups in 9 seconds PocketOS · Apr 1, 2026 | Service disruption | — | Data loss | Mashable ↗ verified |
| Compromised LiteLLM PyPI packages harvest credentials via supply-chain attack LiteLLM (BerriAI) · Mar 24, 2026 | Data breach | — | Credential compromise | LiteLLM (security update) ↗ verified |
| Four-agent LangChain loop runs 11 days and burns $47,000 while dashboards look healthy Teja Kusireddy team (multi-agent research system) · Mar 23, 2026 | Financial loss | $47K | Runaway loop | Waxell (citing primary post-mortem by Teja Kusireddy) ↗ verified |
| Claude Code entered an infinite loop, re-sending the same requests for hours and burning $500+ in tokens Claude Code user (GitHub issue 35166) · Mar 17, 2026 | Financial loss | $500 | Runaway loop | GitHub issue, anthropics/claude-code 35166 ↗ verified |
| Codex extension update left users burning 20% of a weekly token allowance in two hours of ordinary prompts Codex users (openai/codex issue 14593) · Mar 13, 2026 | Financial loss | — | API cost spike | GitHub issue, openai/codex 14593 ↗ verified |
| Replit subscription credits hit 100% on an undeployed prototype; auto-billing invoices $60 beyond the plan Replit (community forum) · Feb 12, 2026 | Financial loss | — | API cost spike | Replit Community Forum - 'Replit Credits Exhausted' (2026-02-12) ↗ verified |
| Step Finance treasury drained in $27–40M exploit Step Finance · Jan 31, 2026 | Financial loss | $30M | Credential compromise | CoinDesk ↗ verified |
| HUMAN Security: AI agent traffic grew 7,851%, 8x faster than human traffic HUMAN Security · Jan 1, 2026 | Service disruption | — | Prompt injection | HUMAN Security ↗ verified |
| AvePoint: 88.4% of organizations hit by at least one AI agent security breach in 12 months AvePoint · Jan 1, 2026 | Data breach | — | Prompt injection | AvePoint ↗ verified |
| Darktrace/CSA: 92% of security pros concerned about AI agent impact Darktrace / Cloud Security Alliance · Jan 1, 2026 | Reputational damage | — | Prompt injection | Darktrace ↗ verified |
| Gartner: worldwide AI spending forecast at $2.52 trillion in 2026, up 44% YoY Gartner / Portal26 · Jan 1, 2026 | Financial loss | — | Cloud cost spike | Portal26 (citing Gartner) ↗ verified |
| TRM Labs: $2.87 billion stolen across ~150 crypto hacks in 2025 TRM Labs · Jan 1, 2026 | Financial loss | $2.9B | Credential compromise | TRM Labs ↗ verified |
| Amazon's Kiro AI agent deletes and recreates part of its AWS environment, causing a 13-hour outage Amazon Web Services · Dec 15, 2025 | Service disruption | — | Data loss | The Guardian ↗ verified |
| Runaway while-loop in Claude agent burns ~$47,000 in API tokens overnight anonymous (engineering post-mortem) · Dec 1, 2025 | Financial loss | $47K | Runaway loop | Post-mortem reshared on LinkedIn ↗ |
| Google's Antigravity IDE vulnerable to data exfiltration and remote code execution via prompt injection Google · Nov 25, 2025 | Data breach | — | Data exfiltration | Embrace The Red ↗ verified |
| SEC charges $12M 'AI crypto trading bot' as a Ponzi scheme Nathan Fuller · Nov 1, 2025 | Legal / liability | $12M | Trading agent failure | Law360 ↗ verified |
| AI agent deletes 1.9 million rows of production data 'thinking it was helping' anonymous developer · Nov 1, 2025 | Service disruption | — | Data loss | Medium (Data and Beyond) ↗ verified |
| State-sponsored group automates ~80–90% of a cyber-espionage operation using Claude Code and MCP tools Anthropic (Claude Code, abused by a threat actor) · Nov 1, 2025 | Data breach | — | Data exfiltration | Anthropic ↗ verified |
| Study: best AI agents complete only ~2% of 240 real Upwork projects Upwork / academic study · Nov 1, 2025 | Reputational damage | — | Coding agent failure | Industry commentary citing the study ↗ |
| Orphaned Claude Code shell stuck in a loop burned 2,000 tokens a minute for nearly 2 days, costing $85 in Cohere API calls Individual developer (r/ClaudeCode report) · Oct 17, 2025 | Financial loss | $85 | Runaway loop | Reddit r/ClaudeCode (first-hand report) ↗ verified |
| Claude Code autocompacting loop spiked token usage until the budget ran out (flagged ACTIVE INCIDENT) Claude Code users (GitHub issue 9579) · Oct 15, 2025 | Financial loss | — | Runaway loop | GitHub issue, anthropics/claude-code 9579 ↗ verified |
| Deloitte refunds part of an AU$440,000 Australian government report over AI-fabricated citations Deloitte Australia · Oct 6, 2025 | Financial loss | — | Hallucinated action | OECD.AI Incidents Monitor ↗ verified |
| Anthropic test agent buys a duplicate snowboard its owner already owns Anthropic · Oct 1, 2025 | Financial loss | — | Unauthorized transaction | Rowan Cheung (summary) ↗ |
| AI trading bot misreads tweet, sends $441K of tokens to a stranger anonymous (OpenAI employee side project) · Oct 1, 2025 | Financial loss | $441K | Trading agent failure | PumpParade (Medium) ↗ |
| Clawdbot trading agent reportedly loses $1,000,000 Clawdbot (open-source project) · Oct 1, 2025 | Financial loss | $1M | Trading agent failure | Developer-community posts ↗ |
| AI agent scanning DN42 racks up $6,500+ AWS bill in 24 hours anonymous developer · Sep 1, 2025 | Financial loss | $2K | Cloud cost spike | Hacker News ↗ verified |
| Prompt injection in Manus turned its sandbox into a publicly-exposed VS Code server with API keys inside Manus (AI agent) · Aug 25, 2025 | Data breach | — | Credential compromise | Embrace The Red (Johann Rehberger) ↗ verified |
| Windsurf Cascade coding agent leaks developer secrets via indirect prompt injection Windsurf (Cascade) · Aug 21, 2025 | Data breach | — | Data exfiltration | Embrace The Red (Johann Rehberger) ↗ verified |
| Lenovo's Lena support chatbot tricked into serving XSS that steals support-agent session cookies Lenovo (Lena chatbot) · Aug 18, 2025 | Reputational damage | — | Prompt injection | CSO Online ↗ verified |
| Google Jules asynchronous coding agent vulnerable to multiple data exfiltration issues Google (Jules) · Aug 13, 2025 | Data breach | — | Data exfiltration | Embrace The Red (Johann Rehberger) ↗ verified |
| GitHub Copilot prompt injection enables remote code execution (CVE-2025-53773) GitHub (Copilot / VS Code) · Aug 12, 2025 | Data breach | — | Coding agent failure | Embrace The Red (Johann Rehberger) ↗ verified |
| Stolen OAuth tokens for Drift AI chatbot expose 700+ Salesforce customers Salesloft (Drift) · Aug 8, 2025 | Data breach | — | Credential compromise | Google Threat Intelligence Group ↗ verified |
| Codex CLI burned platform credits to a negative balance after ChatGPT Plus authentication Shaurya Sethi (OpenAI Codex CLI user) · Aug 7, 2025 | Financial loss | $0 | API cost spike | GitHub issue, openai/codex #1954 ↗ verified |
| Claude Code agent deletes production database after 'terraform destroy' anonymous developer · Aug 1, 2025 | Service disruption | — | Data loss | Medium (Coding Nexus) ↗ verified |
| Gemini CLI's autonomous tool loop silently consumed 47 million tokens on a five-file refactor Individual developer (google-gemini/gemini-cli discussion 4841) · Jul 25, 2025 | Financial loss | $940 | Runaway loop | GitHub discussion, google-gemini/gemini-cli 4841 ↗ verified |
| Replit AI coding agent deletes production database during code freeze Replit · Jul 23, 2025 | Service disruption | — | Data loss | Fortune ↗ verified |
| Google's Gemini CLI hallucinates a directory move and permanently deletes a user's files Google (Gemini CLI) · Jul 21, 2025 | Service disruption | — | Data loss | Mashable ↗ verified |
| Amazon Q for VS Code ships with injected 'wipe the system' prompt Amazon Web Services · Jul 17, 2025 | Reputational damage | — | Prompt injection | SC Media ↗ verified |
| McDonald's McHire AI hiring bot exposes up to 64 million applicants behind the password '123456' McDonald's / Paradox.ai (McHire) · Jul 9, 2025 | Data breach | — | Credential compromise | WIRED ↗ verified |
| Anthropic's Claudius shop agent loses money and insists it is a human in a blazer Anthropic / Andon Labs · Jun 27, 2025 | Financial loss | — | Hallucinated action | Anthropic ↗ verified |
| Cursor's June 2025 pricing switch left Pro users with surprise usage bills and mass refunds Anysphere (Cursor) · Jun 16, 2025 | Financial loss | — | API cost spike | Cursor blog - Clarifying our pricing (2025-07-04) ↗ verified |
| EchoLeak: zero-click prompt injection in Microsoft 365 Copilot exfiltrates internal data (CVE-2025-32711) Microsoft (365 Copilot) · Jun 11, 2025 | Data breach | — | Data exfiltration | Microsoft Security Response Center ↗ verified |
| Claude Opus 4 blackmails engineer to avoid being shut down (safety test) Anthropic · May 22, 2025 | Reputational damage | — | Hallucinated action | Fortune ↗ verified |
| Cursor AI support bot invents fake one-device policy, triggers cancellations Cursor (Anysphere) · Apr 17, 2025 | Reputational damage | — | Hallucinated action | Ars Technica ↗ verified |
| Invariant Labs demonstrates MCP tool poisoning: hidden instructions in tool descriptions exfiltrate data from AI agents Invariant Labs (proof of concept) · Apr 7, 2025 | Data breach | — | Coding agent failure | Invariant Labs ↗ verified |
| AIXBT autonomous agent drained of 55.5 ETH via two malicious prompts queued through its dashboard AIXBT (Virtuals Protocol) · Mar 18, 2025 | Financial loss | $107K | Credential compromise | Decrypt ↗ verified |
| OpenAI Operator AI agent makes surprise smoked-salmon purchase OpenAI · Mar 9, 2025 | Financial loss | — | Unauthorized transaction | The Guardian ↗ verified |
| OpenAI Operator agent makes unauthorized $31.43 grocery purchase OpenAI · Feb 7, 2025 | Financial loss | $31 | Unauthorized transaction | AI Incident Database ↗ verified |
| ChatGPT Operator vulnerable to prompt injection leading to data leaks and unwanted actions OpenAI · Feb 1, 2025 | Data breach | — | Prompt injection | Embrace The Red (Johann Rehberger) ↗ verified |
| Replit Agent stuck in add/remove code loop, burning paid actions with zero progress Replit (community forum) · Jan 25, 2025 | Service disruption | — | Runaway loop | Replit Community Forum - 'Replit agent getting stuck in a loop' (2025-01-25) ↗ verified |
| Devin billed $500/month in ACU credits while failing roughly 85% of assigned tasks Cognition AI (Devin) · Jan 23, 2025 | Financial loss | $500 | API cost spike | The Register ↗ verified |
| OpenAI o3 ARC-AGI benchmark run estimated to cost ~$346,000+ in compute OpenAI · Dec 20, 2024 | Financial loss | $346K | API cost spike | Hacker News (analysis of ARC-AGI run) ↗ verified |
| Freysa AI agent talked into transferring its entire $47,000 prize pool Freysa (adversarial agent game) · Nov 29, 2024 | Financial loss | $47K | Prompt injection | OECD.AI Incidents Monitor ↗ verified |
| Humane recalls AI Pin Charge Case for fire hazard; refunds issued Humane · Oct 31, 2024 | Service disruption | — | Data loss | The Verge ↗ verified |
| Claude Computer Use turned into attacker-controlled 'ZombAI' bot via prompt injection Anthropic (Claude Computer Use) · Oct 24, 2024 | Data breach | — | Prompt injection | Embrace The Red (Johann Rehberger) ↗ verified |
| FTC fines DoNotPay $193,000 for claims its 'robot lawyer' could replace human attorneys DoNotPay · Sep 25, 2024 | Legal / liability | $193K | Hallucinated action | Federal Trade Commission ↗ verified |
| 'SpAIware': ChatGPT memory poisoning turned the assistant into a persistent spy, exfiltrating every future chat OpenAI (ChatGPT memory feature) · Sep 20, 2024 | Data breach | — | Data exfiltration | Embrace The Red (Johann Rehberger) ↗ verified |
| Wallet-drainer disguised as WalletConnect steals $70K+, hits an Ethereum core dev Ethereum core developer · Sep 1, 2024 | Financial loss | $70K | Credential compromise | Cointelegraph ↗ verified |
| Slack AI coaxed into leaking private-channel secrets via a message in a public channel Slack (Salesforce) · Aug 20, 2024 | Data breach | — | Data exfiltration | PromptArmor ↗ verified |
| Sakana's AI Scientist edits its own code to relaunch itself and extend its timeout Sakana AI · Aug 13, 2024 | Service disruption | — | Runaway loop | Ars Technica ↗ verified |
| McDonald's ends AI drive-thru pilot after viral order errors at 100+ restaurants McDonald's / IBM · Jun 17, 2024 | Reputational damage | — | Unauthorized transaction | BBC News ↗ verified |
| GitHub Copilot Chat vulnerable to data exfiltration via prompt injection in untrusted source code GitHub (Copilot Chat) · Jun 14, 2024 | Data breach | — | Data exfiltration | Embrace The Red (Johann Rehberger) ↗ verified |
| Prompt injection in ChatGPT enables user-data exfiltration via images OpenAI · Jun 1, 2024 | Data breach | — | Data exfiltration | arXiv ↗ verified |
| NYC MyCity chatbot tells businesses to break the law City of New York / Microsoft · Mar 29, 2024 | Legal / liability | — | Hallucinated action | The Markup ↗ verified |
| Devin 'first AI software engineer' demo accused of being misleading Cognition AI (Devin) · Mar 12, 2024 | Reputational damage | — | Coding agent failure | The Register ↗ verified |
| Morris II: researchers demonstrate a zero-click worm that propagates between GenAI agents via self-replicating prompts Cornell Tech / Technion (research) · Mar 5, 2024 | Data breach | — | Data exfiltration | arXiv (Cornell Tech / Technion) ↗ verified |
| Air Canada held liable for chatbot's invented bereavement refund policy Air Canada · Feb 14, 2024 | Legal / liability | $812 | Hallucinated action | Ars Technica ↗ verified |
| DPD chatbot swears at customer and trashes its own company DPD · Jan 18, 2024 | Reputational damage | — | Hallucinated action | BBC News ↗ verified |
| Researchers prove slopsquatting: hallucinated 'huggingface-cli' package downloaded 30,000+ times once registered Lasso Security (research) / PyPI ecosystem · Jan 15, 2024 | Reputational damage | — | Coding agent failure | Simon Willison (on Lasso Security research) ↗ verified |
| Chevrolet dealership ChatGPT bot agrees to sell a Tahoe for $1 Chevrolet of Watsonville · Dec 14, 2023 | Reputational damage | — | Prompt injection | Business Insider ↗ verified |
| Meta pulls Galactica science LLM demo after three days of hallucinations Meta AI · Nov 18, 2022 | Service disruption | — | Hallucinated action | MIT Technology Review ↗ verified |
| Microsoft Tay bot turns Nazi-spouting within 16 hours Microsoft · Mar 23, 2016 | Reputational damage | — | Hallucinated action | The Guardian ↗ verified |