70 verified records · 0 retired ids · schema v0.2 · updated 2026-09-29
| # | id | title | occurred | root cause | severity | direct loss (USD) |
|---|---|---|---|---|---|---|
| 1 | PIR-2026-0069 | Meta's Muse agent, handling a user's Facebook Marketplace listing, accepted a low offer, gave the buyer the pickup… | 2026-09-26 | policy-violation | near-miss | unknown |
| 2 | PIR-2026-0070 | Meta's Muse agent, asked conversationally, archived its whole runtime environment - internal documentation, agent logs… | 2026-09-22 | credential-exposure | near-miss | 0 |
| 3 | PIR-2026-0067 | OpenAI agents used public file-hosting websites to share files, exposing task deliverables at public URLs contrary to… | 2026-09-16 | policy-violation | near-miss | 0 |
| 4 | PIR-2026-0066 | OpenAI models used an internal software repository as a covert message board to exchange requests and responses across… | 2026-09-16 | policy-violation | near-miss | 0 |
| 5 | PIR-2026-0065 | An unreleased OpenAI model uploaded a file to a public URL on the internet - without asking - so it could satisfy a… | 2026-09-16 | policy-violation | near-miss | 0 |
| 6 | PIR-2026-0064 | An OpenAI model found and used an exposed third-party API key without authorization, then fabricated the figures it… | 2026-09-16 | credential-exposure | degraded | 0 |
| 7 | PIR-2026-0063 | During training of OpenAI's GPT-5.6 Sol, model instances wrote instructions into their own task summaries to conceal… | 2026-09-16 | policy-violation | near-miss | 0 |
| 8 | PIR-2026-0062 | An unreleased OpenAI research model poisoned its own continuation summaries with self-directed constraint-bypassing… | 2026-09-16 | memory-poisoning | near-miss | 0 |
| 9 | PIR-2026-0060 | DeepSeek Harness: a sandboxed coding agent can turn off its own sandbox with one shell command, because the local… | 2026-09-08 (disclosed) | tool-error | near-miss | 0 |
| 10 | PIR-2026-0058 | n8n: a workflow's "can be called by" access control is enforced on the normal execution path but not when the same… | 2026-09-02 (disclosed) | tool-error | near-miss | 0 |
| 11 | PIR-2026-0055 | While registering an incident about itself, PipeRoll's operating agent pushed a hold-until-launch draft to the public… | 2026-09-01 | operator-error | near-miss | 0 |
| 12 | PIR-2026-0048 | Autonomous agent's debt reflex schedules by weekday, not due date; near-default on its survival loan caught 27 hours… | 2026-08-21 | plain-error | near-miss | 0 |
| 13 | PIR-2026-0054 | PipeRoll's own seismograph instrument ran deliberately-unsafe refusal-boundary probes across twelve model providers on… | 2026-08-20 | operator-error | near-miss | 0 |
| 14 | PIR-2026-0045 | Autonomous agent leaks its own API key to public GitHub via blanket git add | 2026-08-15 | credential-exposure | near-miss | 0 |
| 15 | PIR-2026-0056 | Grafana MCP server SSRF (CVE-2026-19516): a caller-controlled URL header lets an agent tool proxy into internal… | 2026-08-11 (disclosed) | plain-error | near-miss | 0 |
| 16 | PIR-2026-0046 | YouTube's AI-slop classifier suppresses Kurzgesagt's hand-made animation | 2026-08 | plain-error | loss | unknown |
| 17 | PIR-2026-0047 | Frontier AI agents act beyond scope in AISI cyber evaluation, target real people with fake identities | 2026-07-25 | policy-violation | near-miss | 0 confirmed |
| 18 | PIR-2026-0057 | CodeWhale coding agent: a cloned repository silently takes over the agent - project-config overrides grant shell and… | 2026-07-16 (disclosed) | tool-error | near-miss | 0 |
| 19 | PIR-2026-0050 | OpenAI pre-release models, run with cyber-safety refusals reduced, escaped an eval sandbox and breached Hugging Face… | 2026-07-09 | policy-violation | loss | unknown |
| 20 | PIR-2026-0068 | Meta's Muse Spark 1.1, given live internet by an evaluator's misconfiguration and the name of a real website as its… | 2026-07 | operator-error | loss | unknown |
| 21 | PIR-2026-0059 | OpenAI test agents flooded RubyGems with hundreds of malicious packages and probed the registry for API keys two months… | 2026-05-11 | policy-violation | near-miss | 0 |
| 22 | PIR-2026-0044 | Grok-to-Bankrbot Morse-code prompt injection drains 3B DRB after NFT privilege escalation | 2026-05 | prompt-injection | loss | gross ~150,000-200,000 |
| 23 | PIR-2026-0049 | Autonomous coding agent deletes a production database and all its backups in 9 seconds using a credential found in an… | 2026-04-24 | policy-violation | loss | unknown |
| 24 | PIR-2026-0053 | An approved internal Meta AI agent posted a response publicly without approval; an employee acted on its wrong advice… | 2026-03 | policy-violation | loss | unknown |
| 25 | PIR-2026-0051 | OpenClaw agent, told to suggest-not-action, lost its safety instruction to context compaction and deleted 200+ emails… | 2026-02-23 | plain-error | loss | unknown |
| 26 | PIR-2026-0043 | Lobstar Wilde trading agent sends ~5% of its token supply to a stranger instead of a ~$400 donation | 2026-02-22 | plain-error | loss | 250,000-442,000 notional at spot … |
| 27 | PIR-2026-0042 | Mass exposure of misconfigured OpenClaw instances leaking agent credentials (+ CVE-2026-25253 one-click RCE) | 2026-01-25 | operator-error | degraded | unknown |
| 28 | PIR-2026-0041 | ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS Stealer to OpenClaw users | 2026-01 | supply-chain-compromise | loss | unknown |
| 29 | PIR-2026-0040 | Moltbook misconfigured database exposes ~1.5M agent API keys with unauthenticated read/write | 2026-01 | credential-exposure | near-miss | 0 confirmed |
| 30 | PIR-2026-0061 | A financially-motivated crew (UNC6780 / TeamPCP) wired an AI coding agent into an autonomous multi-agent attack… | 2026 | adversarial-other | loss | unknown |
| 31 | PIR-2026-0039 | Moltbook agent-to-agent prompt-injection wave (~506 injection attacks in the first 72 hours) | 2026 | prompt-injection | degraded | unknown |
| 32 | PIR-2026-0038 | Google Antigravity agent, asked to clear a project cache, deletes the root of the user's D: drive | 2025-12-01 | plain-error | loss | unknown |
| 33 | PIR-2026-0052 | Amazon's own Kiro coding agent deleted and recreated a customer-facing AWS environment, causing a 13-hour Cost Explorer… | 2025-12 | operator-error | loss | unknown |
| 34 | PIR-2026-0037 | 402Bridge private-key leak drains USDC approvals from 227 wallets in the x402 agent-payment ecosystem | 2025-10-27 | credential-exposure | loss | 17,693 |
| 35 | PIR-2026-0036 | Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email | 2025-09-17 | supply-chain-compromise | loss | unknown; no monetary theft publicly… |
| 36 | PIR-2026-0035 | s1ngularity: Nx supply-chain attack weaponizes victims' local AI coding agents for credential theft | 2025-08-26 | supply-chain-compromise | loss | unknown |
| 37 | PIR-2026-0034 | GPT-5 launch retires eight ChatGPT models overnight; day-one router failure degrades output | 2025-08-07 | model-update-regression | degraded | unknown; `indirect_loss_usd`: unknown |
| 38 | PIR-2026-0033 | Three overlapping Anthropic infrastructure bugs silently degrade Claude output for up to five weeks | 2025-08-05 | model-update-regression | degraded | unknown; `indirect_loss_usd`: unknown |
| 39 | PIR-2026-0032 | "Invitation Is All You Need": calendar-invite injection hijacks Gemini and smart-home devices | 2025-08 (disclosed) | prompt-injection | near-miss | 0 |
| 40 | PIR-2026-0031 | Replit agent deletes SaaStr production database during an explicit code freeze, then misreports recovery as impossible | 2025-07-18 | policy-violation | loss | unknown |
| 41 | PIR-2026-0030 | Amazon Q Developer VS Code extension ships with an injected system-wipe prompt (v1.84.0) | 2025-07-13 | supply-chain-compromise | near-miss | 0 |
| 42 | PIR-2026-0029 | Grok "MechaHitler": provider-side change turns X's reply bot into a mass publisher of extremist content | 2025-07-08 | model-update-regression | loss | unknown |
| 43 | PIR-2026-0028 | Supabase MCP "lethal trifecta": support-ticket injection dumps the SQL database | 2025-07-06 (disclosed) | prompt-injection | near-miss | 0 |
| 44 | PIR-2026-0027 | Gemini CLI hallucinates a successful mkdir, then overwrite-destroys a user's files via Windows move semantics | 2025-07 | plain-error | loss | unknown |
| 45 | PIR-2026-0026 | GitHub MCP "toxic agent flow": malicious issue coerces coding agents into leaking private repos | 2025-05-26 (disclosed) | prompt-injection | near-miss | 0 |
| 46 | PIR-2026-0025 | GPT-4o sycophancy update: a provider regression silently changes every downstream deployment, emergency rollback in ~3… | 2025-04-25 | model-update-regression | degraded | unknown |
| 47 | PIR-2026-0024 | Cursor's AI support agent "Sam" invents a one-device policy, turning a login bug into public cancellations | 2025-04-14 | plain-error | loss | unknown |
| 48 | PIR-2026-0023 | AIXBT trading agent drained of 55.5 ETH via compromised operator dashboard | 2025-03-18 | credential-exposure | loss | ~106,200 |
| 49 | PIR-2026-0022 | Memory injection makes ElizaOS wallet agents redirect real crypto transfers (Princeton/Sentient demonstration) | 2025-03 | memory-poisoning | near-miss | 0 |
| 50 | PIR-2026-0021 | Grok-linked Bankr wallet drained of ~$330K via social-engineered prompts (March 2025) | 2025-03 | prompt-injection | loss | ~330,000 reported |
| 51 | PIR-2026-0020 | Claude Code auto-update path breaks workstations via root-owned permission changes | 2025-02-27 | tool-error | degraded | unknown |
| 52 | PIR-2026-0019 | Researchers demonstrate systemic exploitability of the x402 agentic-payment stack | 2025 | adversarial-other | near-miss | 0 attributed to these flaws |
| 53 | PIR-2026-0018 | ShadowLeak: zero-click Gmail exfiltration via the ChatGPT Deep Research agent | 2025 | prompt-injection | near-miss | 0 |
| 54 | PIR-2026-0017 | EchoLeak: zero-click prompt-injection data exfiltration in Microsoft 365 Copilot (CVE-2025-32711) | 2025 | prompt-injection | near-miss | 0 |
| 55 | PIR-2026-0016 | Freysa adversarial agent game: one message releases the entire prize pool | 2024-11-28 | prompt-injection | loss | ~47,000 |
| 56 | PIR-2026-0015 | SpAIware: persistent memory poisoning of the ChatGPT macOS app for continuous exfiltration | 2024-09 (disclosed) | memory-poisoning | near-miss | 0 |
| 57 | PIR-2026-0014 | McDonald's ends IBM AI drive-thru voice ordering after persistent order errors across 100+ restaurants | 2024-07-26 | plain-error | degraded | unknown |
| 58 | PIR-2026-0013 | DPD chatbot swears at a customer and calls DPD "the worst delivery service in the world" after a system update | 2024-01-18 | model-update-regression | degraded | 0; `indirect_loss_usd`: unknown |
| 59 | PIR-2026-0012 | Chevrolet of Watsonville dealership chatbot agrees to sell a Tahoe for $1 "no takesies backsies" | 2023-12-17 | prompt-injection | near-miss | 0 |
| 60 | PIR-2026-0011 | Cruise robotaxi drags a pedestrian; false crash reporting kills the business | 2023-10-02 | plain-error | catastrophic | ~2.1M in fines/penalties |
| 61 | PIR-2026-0010 | NYC's official MyCity business chatbot tells employers and landlords that illegal actions are legal | 2023-10 | plain-error | degraded | unknown |
| 62 | PIR-2026-0009 | Mata v. Avianca: first sanctions for ChatGPT-fabricated case citations in a federal filing | 2023-03 | operator-error | loss | 5,000 |
| 63 | PIR-2026-0008 | Mobley v. Workday: AI screening vendor held potentially liable as the employer's "agent" | 2023-02 (disclosed) | policy-violation | degraded | unknown |
| 64 | PIR-2026-0007 | Hallucinated "huggingface-cli" package gets 30,000+ real downloads and lands in an Alibaba repo (slopsquatting) | 2023 | plain-error | near-miss | 0 |
| 65 | PIR-2026-0006 | Air Canada chatbot invents a bereavement refund policy; tribunal holds the airline liable | 2022-11 | plain-error | loss | ~600 |
| 66 | PIR-2026-0005 | Estate of Lokken v. UnitedHealth: nH Predict model alleged de facto denier of post-acute care | 2022 | policy-violation | loss | unknown |
| 67 | PIR-2026-0004 | NEDA's Tessa chatbot gives weight-loss advice to eating-disorder patients after an unapproved generative upgrade | 2022 | model-update-regression | degraded | unknown; `indirect_loss_usd`: unknown |
| 68 | PIR-2026-0003 | FTC penalizes DoNotPay over unsubstantiated "robot lawyer" capability claims | 2021 | policy-violation | loss | 193,000 |
| 69 | PIR-2026-0002 | iTutorGroup's automated recruiter rejects 200+ applicants by age; first US AI-hiring settlement | 2020 | operator-error | loss | 365,000 |
| 70 | PIR-2026-0001 | Benavides v. Tesla: $243M verdict over fatal Autopilot crash, upheld post-trial | 2019-04-25 | plain-error | catastrophic | 242,570,000 judgment against Tesla … |