45 verified records · 0 retired ids · schema v0.2
| # | id | title | occurred | root cause | severity | direct loss |
|---|---|---|---|---|---|---|
| 1 | PIR-2026-0045 | Autonomous agent leaks its own API key to public GitHub via blanket git add | 2026-08-15 | credential-exposure | near-miss | 0 |
| 2 | PIR-2026-0044 | Grok-to-Bankrbot Morse-code prompt injection drains 3B DRB after NFT privilege escalation | 2026-05 | prompt-injection | loss | gross ~150,000-200,000 |
| 3 | PIR-2026-0043 | Lobstar Wilde trading agent sends ~5% of its token supply to a stranger instead of a… | 2026-02-22 | plain-error | loss | 250,000-442,000 notional… |
| 4 | PIR-2026-0042 | Mass exposure of misconfigured OpenClaw instances leaking agent credentials (+… | 2026-01-25 | operator-error | degraded | unknown |
| 5 | PIR-2026-0041 | ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS Stealer to OpenClaw… | 2026-01 | supply-chain-compromise | loss | unknown |
| 6 | PIR-2026-0040 | Moltbook misconfigured database exposes ~1.5M agent API keys with unauthenticated… | 2026-01 | credential-exposure | near-miss | 0 confirmed |
| 7 | PIR-2026-0039 | Moltbook agent-to-agent prompt-injection wave (~506 injection attacks in the first 72… | 2026 | prompt-injection | degraded | unknown |
| 8 | PIR-2026-0038 | Google Antigravity agent, asked to clear a project cache, deletes the root of the user's… | 2025-12-01 | plain-error | loss | unknown |
| 9 | PIR-2026-0037 | 402Bridge private-key leak drains USDC approvals from 227 wallets in the x402… | 2025-10-27 | credential-exposure | loss | 17,693 |
| 10 | PIR-2026-0036 | Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email | 2025-09-17 | supply-chain-compromise | loss | unknown; no monetary… |
| 11 | PIR-2026-0035 | s1ngularity: Nx supply-chain attack weaponizes victims' local AI coding agents for… | 2025-08-26 | supply-chain-compromise | loss | unknown |
| 12 | PIR-2026-0034 | GPT-5 launch retires eight ChatGPT models overnight; day-one router failure degrades… | 2025-08-07 | model-update-regression | degraded | unknown… |
| 13 | PIR-2026-0033 | Three overlapping Anthropic infrastructure bugs silently degrade Claude output for up to… | 2025-08-05 | model-update-regression | degraded | unknown… |
| 14 | PIR-2026-0032 | "Invitation Is All You Need": calendar-invite injection hijacks Gemini and smart-home… | 2025-08 (disclosed) | prompt-injection | near-miss | 0 |
| 15 | PIR-2026-0031 | Replit agent deletes SaaStr production database during an explicit code freeze, then… | 2025-07-18 | policy-violation | loss | unknown |
| 16 | PIR-2026-0030 | Amazon Q Developer VS Code extension ships with an injected system-wipe prompt (v1.84.0) | 2025-07-13 | supply-chain-compromise | near-miss | 0 |
| 17 | PIR-2026-0029 | Grok "MechaHitler": provider-side change turns X's reply bot into a mass publisher of… | 2025-07-08 | model-update-regression | loss | unknown |
| 18 | PIR-2026-0028 | Supabase MCP "lethal trifecta": support-ticket injection dumps the SQL database | 2025-07-06 (disclosed) | prompt-injection | near-miss | 0 |
| 19 | PIR-2026-0027 | Gemini CLI hallucinates a successful mkdir, then overwrite-destroys a user's files via… | 2025-07 | plain-error | loss | unknown |
| 20 | PIR-2026-0026 | GitHub MCP "toxic agent flow": malicious issue coerces coding agents into leaking private… | 2025-05-26 (disclosed) | prompt-injection | near-miss | 0 |
| 21 | PIR-2026-0025 | GPT-4o sycophancy update: a provider regression silently changes every downstream… | 2025-04-25 | model-update-regression | degraded | unknown |
| 22 | PIR-2026-0024 | Cursor's AI support agent "Sam" invents a one-device policy, turning a login bug into… | 2025-04-14 | plain-error | loss | unknown |
| 23 | PIR-2026-0023 | AIXBT trading agent drained of 55.5 ETH via compromised operator dashboard | 2025-03-18 | credential-exposure | loss | ~106,200 |
| 24 | PIR-2026-0022 | Memory injection makes ElizaOS wallet agents redirect real crypto transfers… | 2025-03 | memory-poisoning | near-miss | 0 |
| 25 | PIR-2026-0021 | Grok-linked Bankr wallet drained of ~$330K via social-engineered prompts (March 2025) | 2025-03 | prompt-injection | loss | ~330,000 reported |
| 26 | PIR-2026-0020 | Claude Code auto-update path breaks workstations via root-owned permission changes | 2025-02-27 | tool-error | degraded | unknown |
| 27 | PIR-2026-0019 | Researchers demonstrate systemic exploitability of the x402 agentic-payment stack | 2025 | adversarial-other | near-miss | 0 attributed to these… |
| 28 | PIR-2026-0018 | ShadowLeak: zero-click Gmail exfiltration via the ChatGPT Deep Research agent | 2025 | prompt-injection | near-miss | 0 |
| 29 | PIR-2026-0017 | EchoLeak: zero-click prompt-injection data exfiltration in Microsoft 365 Copilot… | 2025 | prompt-injection | near-miss | 0 |
| 30 | PIR-2026-0016 | Freysa adversarial agent game: one message releases the entire prize pool | 2024-11-28 | prompt-injection | loss | ~47,000 |
| 31 | PIR-2026-0015 | SpAIware: persistent memory poisoning of the ChatGPT macOS app for continuous exfiltration | 2024-09 (disclosed) | memory-poisoning | near-miss | 0 |
| 32 | PIR-2026-0014 | McDonald's ends IBM AI drive-thru voice ordering after persistent order errors across… | 2024-07-26 | plain-error | degraded | unknown |
| 33 | PIR-2026-0013 | DPD chatbot swears at a customer and calls DPD "the worst delivery service in the world"… | 2024-01-18 | model-update-regression | degraded | 0; `indirect_loss_usd`… |
| 34 | PIR-2026-0012 | Chevrolet of Watsonville dealership chatbot agrees to sell a Tahoe for $1 "no takesies… | 2023-12-17 | prompt-injection | near-miss | 0 |
| 35 | PIR-2026-0011 | Cruise robotaxi drags a pedestrian; false crash reporting kills the business | 2023-10-02 | plain-error | catastrophic | ~2.1M in fines/penalties |
| 36 | PIR-2026-0010 | NYC's official MyCity business chatbot tells employers and landlords that illegal actions… | 2023-10 | plain-error | degraded | unknown |
| 37 | PIR-2026-0009 | Mata v. Avianca: first sanctions for ChatGPT-fabricated case citations in a federal filing | 2023-03 | operator-error | loss | 5,000 |
| 38 | PIR-2026-0008 | Mobley v. Workday: AI screening vendor held potentially liable as the employer's "agent" | 2023-02 (disclosed) | policy-violation | degraded | unknown |
| 39 | PIR-2026-0007 | Hallucinated "huggingface-cli" package gets 30,000+ real downloads and lands in an… | 2023 | plain-error | near-miss | 0 |
| 40 | PIR-2026-0006 | Air Canada chatbot invents a bereavement refund policy; tribunal holds the airline liable | 2022-11 | plain-error | loss | ~600 |
| 41 | PIR-2026-0005 | Estate of Lokken v. UnitedHealth: nH Predict model alleged de facto denier of post-acute… | 2022 | policy-violation | loss | unknown |
| 42 | PIR-2026-0004 | NEDA's Tessa chatbot gives weight-loss advice to eating-disorder patients after an… | 2022 | model-update-regression | degraded | unknown… |
| 43 | PIR-2026-0003 | FTC penalizes DoNotPay over unsubstantiated "robot lawyer" capability claims | 2021 | policy-violation | loss | 193,000 |
| 44 | PIR-2026-0002 | iTutorGroup's automated recruiter rejects 200+ applicants by age; first US AI-hiring… | 2020 | operator-error | loss | 365,000 |
| 45 | PIR-2026-0001 | Benavides v. Tesla: $243M verdict over fatal Autopilot crash, upheld post-trial | 2019-04-25 | plain-error | catastrophic | 242,570,000 judgment… |