| NeuralTrust: 34.9% of enterprises report confirmed AI agent security incidents NeuralTrust · Jun 1, 2026 | Financial loss | — | Prompt injection | NeuralTrust - State of AI Agent Security 2026 ↗ verified |
| Claude Opus 4.6 agent deletes PocketOS production DB and backups in 9 seconds PocketOS · Apr 1, 2026 | Service disruption | — | Data loss | Mashable ↗ verified |
| Step Finance treasury drained in $27–40M exploit Step Finance · Jan 31, 2026 | Financial loss | $30M | Credential compromise | CoinDesk ↗ verified |
| HUMAN Security: AI agent traffic grew 7,851%, 8x faster than human traffic HUMAN Security · Jan 1, 2026 | Service disruption | — | Prompt injection | HUMAN Security ↗ verified |
| AvePoint: 88.4% of organizations hit by at least one AI agent security breach in 12 months AvePoint · Jan 1, 2026 | Data breach | — | Prompt injection | AvePoint ↗ verified |
| Darktrace/CSA: 92% of security pros concerned about AI agent impact Darktrace / Cloud Security Alliance · Jan 1, 2026 | Reputational damage | — | Prompt injection | Darktrace ↗ verified |
| Gartner: worldwide AI spending forecast at $2.52 trillion in 2026, up 44% YoY Gartner / Portal26 · Jan 1, 2026 | Financial loss | — | Cloud cost spike | Portal26 (citing Gartner) ↗ verified |
| TRM Labs: $2.87 billion stolen across ~150 crypto hacks in 2025 TRM Labs · Jan 1, 2026 | Financial loss | $2.9B | Credential compromise | TRM Labs ↗ verified |
| Runaway while-loop in Claude agent burns ~$47,000 in API tokens overnight anonymous (engineering post-mortem) · Dec 1, 2025 | Financial loss | $47K | Runaway loop | Post-mortem reshared on LinkedIn ↗ |
| SEC charges $12M 'AI crypto trading bot' as a Ponzi scheme Nathan Fuller · Nov 1, 2025 | Legal / liability | $12M | Trading agent failure | Law360 ↗ verified |
| AI agent deletes 1.9 million rows of production data 'thinking it was helping' anonymous developer · Nov 1, 2025 | Service disruption | — | Data loss | Medium (Data and Beyond) ↗ verified |
| Study: best AI agents complete only ~2% of 240 real Upwork projects Upwork / academic study · Nov 1, 2025 | Reputational damage | — | Coding agent failure | Industry commentary citing the study ↗ |
| Anthropic test agent buys a duplicate snowboard its owner already owns Anthropic · Oct 1, 2025 | Financial loss | — | Unauthorized transaction | Rowan Cheung (summary) ↗ |
| AI trading bot misreads tweet, sends $441K of tokens to a stranger anonymous (OpenAI employee side project) · Oct 1, 2025 | Financial loss | $441K | Trading agent failure | PumpParade (Medium) ↗ |
| Clawdbot trading agent reportedly loses $1,000,000 Clawdbot (open-source project) · Oct 1, 2025 | Financial loss | $1M | Trading agent failure | Developer-community posts ↗ |
| AI agent scanning DN42 racks up $6,500+ AWS bill in 24 hours anonymous developer · Sep 1, 2025 | Financial loss | $2K | Cloud cost spike | Hacker News ↗ verified |
| Claude Code agent deletes production database after 'terraform destroy' anonymous developer · Aug 1, 2025 | Service disruption | — | Data loss | Medium (Coding Nexus) ↗ verified |
| Replit AI coding agent deletes production database during code freeze Replit · Jul 23, 2025 | Service disruption | — | Data loss | Fortune ↗ verified |
| Claude Opus 4 blackmails engineer to avoid being shut down (safety test) Anthropic · May 22, 2025 | Reputational damage | — | Hallucinated action | Fortune ↗ verified |
| Cursor AI support bot invents fake one-device policy, triggers cancellations Cursor (Anysphere) · Apr 17, 2025 | Reputational damage | — | Hallucinated action | Ars Technica ↗ verified |
| OpenAI Operator AI agent makes surprise smoked-salmon purchase OpenAI · Mar 9, 2025 | Financial loss | — | Unauthorized transaction | The Guardian ↗ verified |
| OpenAI Operator agent makes unauthorized $31.43 grocery purchase OpenAI · Feb 7, 2025 | Financial loss | $31 | Unauthorized transaction | AI Incident Database ↗ verified |
| ChatGPT Operator vulnerable to prompt injection leading to data leaks and unwanted actions OpenAI · Feb 1, 2025 | Data breach | — | Prompt injection | Embrace The Red (Johann Rehberger) ↗ verified |
| OpenAI o3 ARC-AGI benchmark run estimated to cost ~$346,000+ in compute OpenAI · Dec 20, 2024 | Financial loss | $346K | API cost spike | Hacker News (analysis of ARC-AGI run) ↗ verified |
| Humane recalls AI Pin Charge Case for fire hazard; refunds issued Humane · Oct 31, 2024 | Service disruption | — | Data loss | The Verge ↗ verified |
| Wallet-drainer disguised as WalletConnect steals $70K+, hits an Ethereum core dev Ethereum core developer · Sep 1, 2024 | Financial loss | $70K | Credential compromise | Cointelegraph ↗ verified |
| Prompt injection in ChatGPT enables user-data exfiltration via images OpenAI · Jun 1, 2024 | Data breach | — | Data exfiltration | arXiv ↗ verified |
| NYC MyCity chatbot tells businesses to break the law City of New York / Microsoft · Mar 29, 2024 | Legal / liability | — | Hallucinated action | The Markup ↗ verified |
| Devin 'first AI software engineer' demo accused of being misleading Cognition AI (Devin) · Mar 12, 2024 | Reputational damage | — | Coding agent failure | The Register ↗ verified |
| Air Canada held liable for chatbot's invented bereavement refund policy Air Canada · Feb 14, 2024 | Legal / liability | $812 | Hallucinated action | Ars Technica ↗ verified |
| DPD chatbot swears at customer and trashes its own company DPD · Jan 18, 2024 | Reputational damage | — | Hallucinated action | BBC News ↗ verified |
| Chevrolet dealership ChatGPT bot agrees to sell a Tahoe for $1 Chevrolet of Watsonville · Dec 14, 2023 | Reputational damage | — | Prompt injection | Business Insider ↗ verified |
| Meta pulls Galactica science LLM demo after three days of hallucinations Meta AI · Nov 18, 2022 | Service disruption | — | Hallucinated action | MIT Technology Review ↗ verified |
| Microsoft Tay bot turns Nazi-spouting within 16 hours Microsoft · Mar 23, 2016 | Reputational damage | — | Hallucinated action | The Guardian ↗ verified |