PipeRoll - Agent Incident Registry

Agent Incident Registry

Verified public records of AI-agent failures - schema, statistics, permalinks

45 verified records · 0 retired ids · schema v0.2

Every record is individually verified against primary sources before publication; corrections are recorded in the record itself. Rejected candidates retire their reserved ids permanently (CVE convention). Id numbering: the initial import (0001-0045, registered Aug 2026) is ordered by occurrence date, oldest first, as a one-time property; from here on ids are assigned at registration, so sequence is not guaranteed chronological for later records. The year in the id is the registration year. This registry is young - treat aggregate statistics as early data, not actuarial tables.

Completeness: this registry records publicly reported, verifiable incidents - a fraction of what occurs. Most agent failures are never disclosed, and coverage skews toward incidents that are visible (on-chain losses, court records, published research) and English-language sources. Counts here are a floor, never an estimate of true frequency; the absence of a system from this registry is not evidence of its safety, and no failure rate can be computed from registry counts alone because the exposure base (how many agents run, doing what) is unknown.

Root cause: plain-error 10 · prompt-injection 10 · model-update-regression 6 · policy-violation 4 · credential-exposure 4 · supply-chain-compromise 4

Severity: loss 19 · near-miss 13 · degraded 11 · catastrophic 2

Exploitation status: in-wild-malfunction 23 · researcher-demonstrated 10 · in-wild-exploited 10 · bounty-game 1 · in-wild-payload-failed 1

#idtitleoccurredroot causeseveritydirect loss
1PIR-2026-0045Autonomous agent leaks its own API key to public GitHub via blanket git add2026-08-15credential-exposurenear-miss0
2PIR-2026-0044Grok-to-Bankrbot Morse-code prompt injection drains 3B DRB after NFT privilege escalation2026-05prompt-injectionlossgross ~150,000-200,000
3PIR-2026-0043Lobstar Wilde trading agent sends ~5% of its token supply to a stranger instead of a…2026-02-22plain-errorloss250,000-442,000 notional…
4PIR-2026-0042Mass exposure of misconfigured OpenClaw instances leaking agent credentials (+…2026-01-25operator-errordegradedunknown
5PIR-2026-0041ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS Stealer to OpenClaw…2026-01supply-chain-compromiselossunknown
6PIR-2026-0040Moltbook misconfigured database exposes ~1.5M agent API keys with unauthenticated…2026-01credential-exposurenear-miss0 confirmed
7PIR-2026-0039Moltbook agent-to-agent prompt-injection wave (~506 injection attacks in the first 72…2026prompt-injectiondegradedunknown
8PIR-2026-0038Google Antigravity agent, asked to clear a project cache, deletes the root of the user's…2025-12-01plain-errorlossunknown
9PIR-2026-0037402Bridge private-key leak drains USDC approvals from 227 wallets in the x402…2025-10-27credential-exposureloss17,693
10PIR-2026-0036Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email2025-09-17supply-chain-compromiselossunknown; no monetary…
11PIR-2026-0035s1ngularity: Nx supply-chain attack weaponizes victims' local AI coding agents for…2025-08-26supply-chain-compromiselossunknown
12PIR-2026-0034GPT-5 launch retires eight ChatGPT models overnight; day-one router failure degrades…2025-08-07model-update-regressiondegradedunknown…
13PIR-2026-0033Three overlapping Anthropic infrastructure bugs silently degrade Claude output for up to…2025-08-05model-update-regressiondegradedunknown…
14PIR-2026-0032"Invitation Is All You Need": calendar-invite injection hijacks Gemini and smart-home…2025-08 (disclosed)prompt-injectionnear-miss0
15PIR-2026-0031Replit agent deletes SaaStr production database during an explicit code freeze, then…2025-07-18policy-violationlossunknown
16PIR-2026-0030Amazon Q Developer VS Code extension ships with an injected system-wipe prompt (v1.84.0)2025-07-13supply-chain-compromisenear-miss0
17PIR-2026-0029Grok "MechaHitler": provider-side change turns X's reply bot into a mass publisher of…2025-07-08model-update-regressionlossunknown
18PIR-2026-0028Supabase MCP "lethal trifecta": support-ticket injection dumps the SQL database2025-07-06 (disclosed)prompt-injectionnear-miss0
19PIR-2026-0027Gemini CLI hallucinates a successful mkdir, then overwrite-destroys a user's files via…2025-07plain-errorlossunknown
20PIR-2026-0026GitHub MCP "toxic agent flow": malicious issue coerces coding agents into leaking private…2025-05-26 (disclosed)prompt-injectionnear-miss0
21PIR-2026-0025GPT-4o sycophancy update: a provider regression silently changes every downstream…2025-04-25model-update-regressiondegradedunknown
22PIR-2026-0024Cursor's AI support agent "Sam" invents a one-device policy, turning a login bug into…2025-04-14plain-errorlossunknown
23PIR-2026-0023AIXBT trading agent drained of 55.5 ETH via compromised operator dashboard2025-03-18credential-exposureloss~106,200
24PIR-2026-0022Memory injection makes ElizaOS wallet agents redirect real crypto transfers…2025-03memory-poisoningnear-miss0
25PIR-2026-0021Grok-linked Bankr wallet drained of ~$330K via social-engineered prompts (March 2025)2025-03prompt-injectionloss~330,000 reported
26PIR-2026-0020Claude Code auto-update path breaks workstations via root-owned permission changes2025-02-27tool-errordegradedunknown
27PIR-2026-0019Researchers demonstrate systemic exploitability of the x402 agentic-payment stack2025adversarial-othernear-miss0 attributed to these…
28PIR-2026-0018ShadowLeak: zero-click Gmail exfiltration via the ChatGPT Deep Research agent2025prompt-injectionnear-miss0
29PIR-2026-0017EchoLeak: zero-click prompt-injection data exfiltration in Microsoft 365 Copilot…2025prompt-injectionnear-miss0
30PIR-2026-0016Freysa adversarial agent game: one message releases the entire prize pool2024-11-28prompt-injectionloss~47,000
31PIR-2026-0015SpAIware: persistent memory poisoning of the ChatGPT macOS app for continuous exfiltration2024-09 (disclosed)memory-poisoningnear-miss0
32PIR-2026-0014McDonald's ends IBM AI drive-thru voice ordering after persistent order errors across…2024-07-26plain-errordegradedunknown
33PIR-2026-0013DPD chatbot swears at a customer and calls DPD "the worst delivery service in the world"…2024-01-18model-update-regressiondegraded0; `indirect_loss_usd`…
34PIR-2026-0012Chevrolet of Watsonville dealership chatbot agrees to sell a Tahoe for $1 "no takesies…2023-12-17prompt-injectionnear-miss0
35PIR-2026-0011Cruise robotaxi drags a pedestrian; false crash reporting kills the business2023-10-02plain-errorcatastrophic~2.1M in fines/penalties
36PIR-2026-0010NYC's official MyCity business chatbot tells employers and landlords that illegal actions…2023-10plain-errordegradedunknown
37PIR-2026-0009Mata v. Avianca: first sanctions for ChatGPT-fabricated case citations in a federal filing2023-03operator-errorloss5,000
38PIR-2026-0008Mobley v. Workday: AI screening vendor held potentially liable as the employer's "agent"2023-02 (disclosed)policy-violationdegradedunknown
39PIR-2026-0007Hallucinated "huggingface-cli" package gets 30,000+ real downloads and lands in an…2023plain-errornear-miss0
40PIR-2026-0006Air Canada chatbot invents a bereavement refund policy; tribunal holds the airline liable2022-11plain-errorloss~600
41PIR-2026-0005Estate of Lokken v. UnitedHealth: nH Predict model alleged de facto denier of post-acute…2022policy-violationlossunknown
42PIR-2026-0004NEDA's Tessa chatbot gives weight-loss advice to eating-disorder patients after an…2022model-update-regressiondegradedunknown…
43PIR-2026-0003FTC penalizes DoNotPay over unsubstantiated "robot lawyer" capability claims2021policy-violationloss193,000
44PIR-2026-0002iTutorGroup's automated recruiter rejects 200+ applicants by age; first US AI-hiring…2020operator-errorloss365,000
45PIR-2026-0001Benavides v. Tesla: $243M verdict over fatal Autopilot crash, upheld post-trial2019-04-25plain-errorcatastrophic242,570,000 judgment…