Home/Incident database
Open data · CC BY 4.0 · 95 records

The AI Agent Incident Database

A sourced, public record of every time an autonomous AI agent lost money, leaked data, or did something its operator didn't intend. 85 documented incidents, tracked loss exposure of $557M, spanning 2016–2026. Built so the industry stops learning the same lesson twice.

85
Documented incidents
$557M
Tracked loss exposure
90
Verified records
2016–2026
Years covered

All incidents & statistics

Filter by failure mode · click a row for the full sourced breakdown
IncidentOutcomeLossFailure modeSource
OpenAI Codex stuck in a 9-hour compaction loop drained an entire weekly usage allowance
Codex user (OpenAI Developer Community) · Aug 25, 2026
Financial lossRunaway loopOpenAI Developer Community (first-hand report) ↗ verified
Codex Windows app exhausted a weekly usage limit in about 62 hours across many parallel tasks
lty418905-blip (OpenAI Codex user) · Aug 5, 2026
Financial loss$0API cost spikeGitHub issue, openai/codex #37090 ↗ verified
Microsoft EVP: 'tokenmaxxing is not what we are optimizing for' - division-level AI token budgets imposed as engineers spend thousands each per month
Microsoft · Aug 4, 2026
Financial lossCloud cost spikeThe Next Web (citing 404 Media and an internal Microsoft email) ↗ verified
Codex context auto-compaction loop rereads files, loses progress, and burns paid credits
edisonjoao1 (OpenAI Codex user) · Jul 24, 2026
Financial loss$0API cost spikeGitHub issue, openai/codex #35226 ↗ verified
Three-person agency hit with a $14,000 AWS Bedrock bill after attackers burn stolen keys on Claude
Amazon Bedrock (customer: three-person agency) · Jul 16, 2026
Financial loss$14KCloud cost spikeInfoQ ↗ verified
Replit Agent's effort-based billing hits $50/hour as looping inflates billable actions
Replit Agent users · Jul 16, 2026
Financial lossRunaway loopReddit r/replit - 'Replit's AI Agent is now charging me $50/hour' (2026-07-16) ↗ verified
Stolen EC2 keys burn $14,000 in a single day on Amazon Bedrock
anonymous three-person agency · Jul 16, 2026
Financial loss$14KCredential compromiseInfoQ (citing Tobias Schmidt, AWS consultant, LinkedIn post) ↗ verified
OpenAI confirmed Codex background tasks were silently burning users' usage limits faster than normal
OpenAI (Codex) · Jun 30, 2026
Financial lossAPI cost spikeBusiness Insider ↗ verified
Codex Runtime stuck in a runaway inference loop burned credits with no project loaded
TWembley (OpenAI Codex Runtime user) · Jun 25, 2026
Financial loss$0API cost spikeGitHub issue, openai/codex #30061 ↗ verified
15 malicious JetBrains plugins silently exfiltrated developers' OpenAI, DeepSeek and SiliconFlow API keys
JetBrains Marketplace (third-party plugin authors) · Jun 10, 2026
Data breachCredential compromiseBleepingComputer ↗ verified
Uber burns through its entire 2026 AI coding budget in four months
Uber · Jun 2, 2026
Financial lossAPI cost spikeTechCrunch ↗ verified
NeuralTrust: 34.9% of enterprises report confirmed AI agent security incidents
NeuralTrust · Jun 1, 2026
Financial lossPrompt injectionNeuralTrust - State of AI Agent Security 2026 ↗ verified
SEC charges Texas man with $12.3M fraud over nonexistent 'AI trading bots'
Nathan Fuller (Cypress, Texas) · May 28, 2026
Legal / liability$12MTrading agent failureInvestmentNews (SEC action) ↗ verified
Company hit with a reported $500 million Claude bill after leaving usage limits off
Unnamed enterprise (reported via Axios) · May 28, 2026
Financial loss$500MAPI cost spikeTechCrunch (citing Axios) ↗ verified
AWS user faces a $30K–$38K Bedrock bill that cost-anomaly detection never flagged
AWS Bedrock customer (individual developer) · May 14, 2026
Financial loss$30K–$38KCloud cost spikeThe Register ↗ verified
Stolen Google Cloud API keys run up $3K–$127K Gemini bills for developers
Google Cloud customers (multiple developers) · May 13, 2026
Financial loss$3K–$127KCloud cost spikeThe Register ↗ verified
Google Cloud customers receive tens of thousands in unauthorized API bills after key exposure
Google Cloud (affected customers: Prentus, Fonseka) · May 13, 2026
Financial loss$10KCloud cost spikeThe Register ↗ verified
Stanford Digital Economy Lab: agentic coding tasks consume ~1,000x more tokens than chat, with up to 30x variance on the same task
Stanford Digital Economy Lab · May 5, 2026
Financial lossRunaway loopStanford Digital Economy Lab ↗ verified
Morse-code prompt injection tricks Grok and Bankrbot into draining $150K-$200K in tokens
anonymous wallet operator (Grok / Bankrbot) · May 4, 2026
Financial loss$155KUnauthorized transactionOECD.AI Incidents Monitor ↗ verified
OpenAI Codex escalates to root by exploiting Docker group membership to overwrite a system config
OpenAI (Codex) · May 1, 2026
Service disruptionCoding agent failureOso (AI Agents Gone Rogue registry) ↗ verified
Forgotten /loop command checking PRs every 30 minutes ran 46 times over 26 hours and burned ~$6,000 overnight
Individual developer (r/ClaudeAI report) · May 1, 2026
Financial loss$6KRunaway loopReddit r/ClaudeAI (first-hand report) ↗ verified
Claude Opus co-authors a malicious npm commit that compromises a crypto trading agent
crypto trading agent operator (npm dependency victim) · Apr 29, 2026
Financial lossTrading agent failureOECD.AI Incidents Monitor (corroborated by Infosecurity Magazine and Cryptopolitan) ↗ verified
Lovable users report 400 credits in two weeks lost to agent regression loops
Lovable (user reports) · Apr 15, 2026
Financial lossRunaway loopAfterbuild Labs - 'Lovable burning credits: stop spiral' (2026-04-15) ↗ verified
Claude Opus 4.6 agent deletes PocketOS production DB and backups in 9 seconds
PocketOS · Apr 1, 2026
Service disruptionData lossMashable ↗ verified
Compromised LiteLLM PyPI packages harvest credentials via supply-chain attack
LiteLLM (BerriAI) · Mar 24, 2026
Data breachCredential compromiseLiteLLM (security update) ↗ verified
Four-agent LangChain loop runs 11 days and burns $47,000 while dashboards look healthy
Teja Kusireddy team (multi-agent research system) · Mar 23, 2026
Financial loss$47KRunaway loopWaxell (citing primary post-mortem by Teja Kusireddy) ↗ verified
Claude Code entered an infinite loop, re-sending the same requests for hours and burning $500+ in tokens
Claude Code user (GitHub issue 35166) · Mar 17, 2026
Financial loss$500Runaway loopGitHub issue, anthropics/claude-code 35166 ↗ verified
Codex extension update left users burning 20% of a weekly token allowance in two hours of ordinary prompts
Codex users (openai/codex issue 14593) · Mar 13, 2026
Financial lossAPI cost spikeGitHub issue, openai/codex 14593 ↗ verified
Replit subscription credits hit 100% on an undeployed prototype; auto-billing invoices $60 beyond the plan
Replit (community forum) · Feb 12, 2026
Financial lossAPI cost spikeReplit Community Forum - 'Replit Credits Exhausted' (2026-02-12) ↗ verified
Step Finance treasury drained in $27–40M exploit
Step Finance · Jan 31, 2026
Financial loss$30MCredential compromiseCoinDesk ↗ verified
HUMAN Security: AI agent traffic grew 7,851%, 8x faster than human traffic
HUMAN Security · Jan 1, 2026
Service disruptionPrompt injectionHUMAN Security ↗ verified
AvePoint: 88.4% of organizations hit by at least one AI agent security breach in 12 months
AvePoint · Jan 1, 2026
Data breachPrompt injectionAvePoint ↗ verified
Darktrace/CSA: 92% of security pros concerned about AI agent impact
Darktrace / Cloud Security Alliance · Jan 1, 2026
Reputational damagePrompt injectionDarktrace ↗ verified
Gartner: worldwide AI spending forecast at $2.52 trillion in 2026, up 44% YoY
Gartner / Portal26 · Jan 1, 2026
Financial lossCloud cost spikePortal26 (citing Gartner) ↗ verified
TRM Labs: $2.87 billion stolen across ~150 crypto hacks in 2025
TRM Labs · Jan 1, 2026
Financial loss$2.9BCredential compromiseTRM Labs ↗ verified
Amazon's Kiro AI agent deletes and recreates part of its AWS environment, causing a 13-hour outage
Amazon Web Services · Dec 15, 2025
Service disruptionData lossThe Guardian ↗ verified
Runaway while-loop in Claude agent burns ~$47,000 in API tokens overnight
anonymous (engineering post-mortem) · Dec 1, 2025
Financial loss$47KRunaway loopPost-mortem reshared on LinkedIn ↗
Google's Antigravity IDE vulnerable to data exfiltration and remote code execution via prompt injection
Google · Nov 25, 2025
Data breachData exfiltrationEmbrace The Red ↗ verified
SEC charges $12M 'AI crypto trading bot' as a Ponzi scheme
Nathan Fuller · Nov 1, 2025
Legal / liability$12MTrading agent failureLaw360 ↗ verified
AI agent deletes 1.9 million rows of production data 'thinking it was helping'
anonymous developer · Nov 1, 2025
Service disruptionData lossMedium (Data and Beyond) ↗ verified
State-sponsored group automates ~80–90% of a cyber-espionage operation using Claude Code and MCP tools
Anthropic (Claude Code, abused by a threat actor) · Nov 1, 2025
Data breachData exfiltrationAnthropic ↗ verified
Study: best AI agents complete only ~2% of 240 real Upwork projects
Upwork / academic study · Nov 1, 2025
Reputational damageCoding agent failureIndustry commentary citing the study ↗
Orphaned Claude Code shell stuck in a loop burned 2,000 tokens a minute for nearly 2 days, costing $85 in Cohere API calls
Individual developer (r/ClaudeCode report) · Oct 17, 2025
Financial loss$85Runaway loopReddit r/ClaudeCode (first-hand report) ↗ verified
Claude Code autocompacting loop spiked token usage until the budget ran out (flagged ACTIVE INCIDENT)
Claude Code users (GitHub issue 9579) · Oct 15, 2025
Financial lossRunaway loopGitHub issue, anthropics/claude-code 9579 ↗ verified
Deloitte refunds part of an AU$440,000 Australian government report over AI-fabricated citations
Deloitte Australia · Oct 6, 2025
Financial lossHallucinated actionOECD.AI Incidents Monitor ↗ verified
Anthropic test agent buys a duplicate snowboard its owner already owns
Anthropic · Oct 1, 2025
Financial lossUnauthorized transactionRowan Cheung (summary) ↗
AI trading bot misreads tweet, sends $441K of tokens to a stranger
anonymous (OpenAI employee side project) · Oct 1, 2025
Financial loss$441KTrading agent failurePumpParade (Medium) ↗
Clawdbot trading agent reportedly loses $1,000,000
Clawdbot (open-source project) · Oct 1, 2025
Financial loss$1MTrading agent failureDeveloper-community posts ↗
AI agent scanning DN42 racks up $6,500+ AWS bill in 24 hours
anonymous developer · Sep 1, 2025
Financial loss$2KCloud cost spikeHacker News ↗ verified
Prompt injection in Manus turned its sandbox into a publicly-exposed VS Code server with API keys inside
Manus (AI agent) · Aug 25, 2025
Data breachCredential compromiseEmbrace The Red (Johann Rehberger) ↗ verified
Windsurf Cascade coding agent leaks developer secrets via indirect prompt injection
Windsurf (Cascade) · Aug 21, 2025
Data breachData exfiltrationEmbrace The Red (Johann Rehberger) ↗ verified
Lenovo's Lena support chatbot tricked into serving XSS that steals support-agent session cookies
Lenovo (Lena chatbot) · Aug 18, 2025
Reputational damagePrompt injectionCSO Online ↗ verified
Google Jules asynchronous coding agent vulnerable to multiple data exfiltration issues
Google (Jules) · Aug 13, 2025
Data breachData exfiltrationEmbrace The Red (Johann Rehberger) ↗ verified
GitHub Copilot prompt injection enables remote code execution (CVE-2025-53773)
GitHub (Copilot / VS Code) · Aug 12, 2025
Data breachCoding agent failureEmbrace The Red (Johann Rehberger) ↗ verified
Stolen OAuth tokens for Drift AI chatbot expose 700+ Salesforce customers
Salesloft (Drift) · Aug 8, 2025
Data breachCredential compromiseGoogle Threat Intelligence Group ↗ verified
Codex CLI burned platform credits to a negative balance after ChatGPT Plus authentication
Shaurya Sethi (OpenAI Codex CLI user) · Aug 7, 2025
Financial loss$0API cost spikeGitHub issue, openai/codex #1954 ↗ verified
Claude Code agent deletes production database after 'terraform destroy'
anonymous developer · Aug 1, 2025
Service disruptionData lossMedium (Coding Nexus) ↗ verified
Gemini CLI's autonomous tool loop silently consumed 47 million tokens on a five-file refactor
Individual developer (google-gemini/gemini-cli discussion 4841) · Jul 25, 2025
Financial loss$940Runaway loopGitHub discussion, google-gemini/gemini-cli 4841 ↗ verified
Replit AI coding agent deletes production database during code freeze
Replit · Jul 23, 2025
Service disruptionData lossFortune ↗ verified
Google's Gemini CLI hallucinates a directory move and permanently deletes a user's files
Google (Gemini CLI) · Jul 21, 2025
Service disruptionData lossMashable ↗ verified
Amazon Q for VS Code ships with injected 'wipe the system' prompt
Amazon Web Services · Jul 17, 2025
Reputational damagePrompt injectionSC Media ↗ verified
McDonald's McHire AI hiring bot exposes up to 64 million applicants behind the password '123456'
McDonald's / Paradox.ai (McHire) · Jul 9, 2025
Data breachCredential compromiseWIRED ↗ verified
Anthropic's Claudius shop agent loses money and insists it is a human in a blazer
Anthropic / Andon Labs · Jun 27, 2025
Financial lossHallucinated actionAnthropic ↗ verified
Cursor's June 2025 pricing switch left Pro users with surprise usage bills and mass refunds
Anysphere (Cursor) · Jun 16, 2025
Financial lossAPI cost spikeCursor blog - Clarifying our pricing (2025-07-04) ↗ verified
EchoLeak: zero-click prompt injection in Microsoft 365 Copilot exfiltrates internal data (CVE-2025-32711)
Microsoft (365 Copilot) · Jun 11, 2025
Data breachData exfiltrationMicrosoft Security Response Center ↗ verified
Claude Opus 4 blackmails engineer to avoid being shut down (safety test)
Anthropic · May 22, 2025
Reputational damageHallucinated actionFortune ↗ verified
Cursor AI support bot invents fake one-device policy, triggers cancellations
Cursor (Anysphere) · Apr 17, 2025
Reputational damageHallucinated actionArs Technica ↗ verified
Invariant Labs demonstrates MCP tool poisoning: hidden instructions in tool descriptions exfiltrate data from AI agents
Invariant Labs (proof of concept) · Apr 7, 2025
Data breachCoding agent failureInvariant Labs ↗ verified
AIXBT autonomous agent drained of 55.5 ETH via two malicious prompts queued through its dashboard
AIXBT (Virtuals Protocol) · Mar 18, 2025
Financial loss$107KCredential compromiseDecrypt ↗ verified
OpenAI Operator AI agent makes surprise smoked-salmon purchase
OpenAI · Mar 9, 2025
Financial lossUnauthorized transactionThe Guardian ↗ verified
OpenAI Operator agent makes unauthorized $31.43 grocery purchase
OpenAI · Feb 7, 2025
Financial loss$31Unauthorized transactionAI Incident Database ↗ verified
ChatGPT Operator vulnerable to prompt injection leading to data leaks and unwanted actions
OpenAI · Feb 1, 2025
Data breachPrompt injectionEmbrace The Red (Johann Rehberger) ↗ verified
Replit Agent stuck in add/remove code loop, burning paid actions with zero progress
Replit (community forum) · Jan 25, 2025
Service disruptionRunaway loopReplit Community Forum - 'Replit agent getting stuck in a loop' (2025-01-25) ↗ verified
Devin billed $500/month in ACU credits while failing roughly 85% of assigned tasks
Cognition AI (Devin) · Jan 23, 2025
Financial loss$500API cost spikeThe Register ↗ verified
OpenAI o3 ARC-AGI benchmark run estimated to cost ~$346,000+ in compute
OpenAI · Dec 20, 2024
Financial loss$346KAPI cost spikeHacker News (analysis of ARC-AGI run) ↗ verified
Freysa AI agent talked into transferring its entire $47,000 prize pool
Freysa (adversarial agent game) · Nov 29, 2024
Financial loss$47KPrompt injectionOECD.AI Incidents Monitor ↗ verified
Humane recalls AI Pin Charge Case for fire hazard; refunds issued
Humane · Oct 31, 2024
Service disruptionData lossThe Verge ↗ verified
Claude Computer Use turned into attacker-controlled 'ZombAI' bot via prompt injection
Anthropic (Claude Computer Use) · Oct 24, 2024
Data breachPrompt injectionEmbrace The Red (Johann Rehberger) ↗ verified
FTC fines DoNotPay $193,000 for claims its 'robot lawyer' could replace human attorneys
DoNotPay · Sep 25, 2024
Legal / liability$193KHallucinated actionFederal Trade Commission ↗ verified
'SpAIware': ChatGPT memory poisoning turned the assistant into a persistent spy, exfiltrating every future chat
OpenAI (ChatGPT memory feature) · Sep 20, 2024
Data breachData exfiltrationEmbrace The Red (Johann Rehberger) ↗ verified
Wallet-drainer disguised as WalletConnect steals $70K+, hits an Ethereum core dev
Ethereum core developer · Sep 1, 2024
Financial loss$70KCredential compromiseCointelegraph ↗ verified
Slack AI coaxed into leaking private-channel secrets via a message in a public channel
Slack (Salesforce) · Aug 20, 2024
Data breachData exfiltrationPromptArmor ↗ verified
Sakana's AI Scientist edits its own code to relaunch itself and extend its timeout
Sakana AI · Aug 13, 2024
Service disruptionRunaway loopArs Technica ↗ verified
McDonald's ends AI drive-thru pilot after viral order errors at 100+ restaurants
McDonald's / IBM · Jun 17, 2024
Reputational damageUnauthorized transactionBBC News ↗ verified
GitHub Copilot Chat vulnerable to data exfiltration via prompt injection in untrusted source code
GitHub (Copilot Chat) · Jun 14, 2024
Data breachData exfiltrationEmbrace The Red (Johann Rehberger) ↗ verified
Prompt injection in ChatGPT enables user-data exfiltration via images
OpenAI · Jun 1, 2024
Data breachData exfiltrationarXiv ↗ verified
NYC MyCity chatbot tells businesses to break the law
City of New York / Microsoft · Mar 29, 2024
Legal / liabilityHallucinated actionThe Markup ↗ verified
Devin 'first AI software engineer' demo accused of being misleading
Cognition AI (Devin) · Mar 12, 2024
Reputational damageCoding agent failureThe Register ↗ verified
Morris II: researchers demonstrate a zero-click worm that propagates between GenAI agents via self-replicating prompts
Cornell Tech / Technion (research) · Mar 5, 2024
Data breachData exfiltrationarXiv (Cornell Tech / Technion) ↗ verified
Air Canada held liable for chatbot's invented bereavement refund policy
Air Canada · Feb 14, 2024
Legal / liability$812Hallucinated actionArs Technica ↗ verified
DPD chatbot swears at customer and trashes its own company
DPD · Jan 18, 2024
Reputational damageHallucinated actionBBC News ↗ verified
Researchers prove slopsquatting: hallucinated 'huggingface-cli' package downloaded 30,000+ times once registered
Lasso Security (research) / PyPI ecosystem · Jan 15, 2024
Reputational damageCoding agent failureSimon Willison (on Lasso Security research) ↗ verified
Chevrolet dealership ChatGPT bot agrees to sell a Tahoe for $1
Chevrolet of Watsonville · Dec 14, 2023
Reputational damagePrompt injectionBusiness Insider ↗ verified
Meta pulls Galactica science LLM demo after three days of hallucinations
Meta AI · Nov 18, 2022
Service disruptionHallucinated actionMIT Technology Review ↗ verified
Microsoft Tay bot turns Nazi-spouting within 16 hours
Microsoft · Mar 23, 2016
Reputational damageHallucinated actionThe Guardian ↗ verified

Loss figures are point estimates where a single number is reported, or the reported range. Figures marked verified are confirmed against a primary or major-secondary source. Aggregate statistics (e.g. “88.4% of organizations breached”) are listed separately and labelled statistic.

Download the open dataset

The full database is public and CC BY 4.0. Cite it, fork it, or wire it into your own research.

JSON

Full structured records, pretty-printed.

CSV

Flat table for spreadsheets & BI tools.

JSON Lines

One record per line — stream it into a pipeline.

Open-data repository

The canonical, versioned dataset lives on GitHub and is kept in sync with this site. Fork it, submit an incident, or mirror it: https://github.com/kindrat86/ai-agent-incident-database. See aggregate statistics & charts →

Frequently asked

What is the AI Agent Incident Database?
A curated, sourced record of real-world incidents in which autonomous AI agents caused financial loss, data loss, or unintended actions. Every entry links to a public source — a news article, post-mortem, security report, or official statement.
Is the dataset free to use?
Yes. The full dataset is licensed CC BY 4.0 and available as JSON, CSV, and JSON Lines at /data/ai-agent-incidents.json. Attribution to sipi.bot is required.
How current is the data?
The database covers incidents from 2016 through 2026. It currently holds 85 documented incidents and 10 aggregate statistics, of which 90 are verified against primary sources.
How does this relate to sipi.bot?
sipi.bot is a pre-spend firewall for autonomous AI agents. Each incident page includes a 'How a spend firewall would have helped' note mapping the incident to the firewall's six rule types: per-transaction caps, daily totals, velocity limits, merchant allowlists, category rules, and approval thresholds.
How do I report a new incident?
Open an issue or PR on the open-data repository (https://github.com/kindrat86/ai-agent-incident-database) with a link to a credible public source. We review submissions weekly.

Every incident here is preventable

A spend firewall returns APPROVED, BLOCKED, or FLAGGED before an agent's action takes effect — independent of what the prompt says. Per-transaction caps stop the $441K transfer. Velocity limits stop the runaway loop. Merchant allowlists stop the wallet drainer. The policy, not the prompt, is the control.