{
 "registry": "PipeRoll Agent Incident Registry",
 "generated_from": "incidents/*.md",
 "records": [
  {
   "id": "PIR-2026-0001",
   "title": "Benavides v. Tesla: $243M verdict over fatal Autopilot crash, upheld post-trial",
   "date_occurred": "2019-04-25 (crash, Key Largo FL)",
   "date_disclosed": "jury verdict 2025-08-01 (S.D. Fla., Miami); verdict upheld 2026-02-20 (Judge Beth Bloom); appellate review continuing",
   "root_cause": "plain-error (primary - no adversary; the automation continued at speed through an intersection it was not designed for); contributing operator-error (driver inattention; use outside the operational design domain that the design permitted)",
   "failure_locus": "agent-reasoning (primary - the design failures the jury priced: no enforcement of the operational design domain, no stop-sign response; contributing operator locus: distracted driver carried 67% of fault. Previously recorded as \"shared\" - the fault split lives here in prose, one primary token per v0.2)",
   "severity": "catastrophic (one death, one severe permanent injury)",
   "exploitation_status": "in-wild-malfunction (real crash, real deaths, no attacker - reclassified from in-wild-exploited, which implies an adversary; adversary_present is no)",
   "direct_loss_usd": "242,570,000 judgment against Tesla - not final; appeal continuing as of Aug 2026",
   "status": "corroborated (verdict and post-trial ruling on public record; dollar amount not final pending appeal)",
   "confidence": "high on verdict, breakdown, and post-trial ruling; the loss figure is conservative-flagged as non-final (appellate review pending).",
   "telemetry_grade": "operator-logs (vehicle/fleet telemetry in Tesla's custody; availability and completeness of crash data were themselves contested at trial)",
   "operator_type": "individual (driver) atop an enterprise-provided automation stack",
   "blast_radius": "public (third parties outside the vehicle were the ones killed and injured)",
   "url": "pir/2026-0001/",
   "cause_key": "plain-error",
   "severity_key": "catastrophic",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2019-04-25",
   "year_key": "2019"
  },
  {
   "id": "PIR-2026-0002",
   "title": "iTutorGroup's automated recruiter rejects 200+ applicants by age; first US AI-hiring settlement",
   "date_occurred": "2020 (automated rejections)",
   "date_disclosed": "2022-05-05 (EEOC suit filed, E.D.N.Y., 1:22-cv-02565); settlement filed 2023-08-09",
   "root_cause": "operator-error - primary: deliberate discriminatory configuration. Contributing: policy-violation (automated execution of an ADEA-illegal rule at scale)",
   "failure_locus": "operator-config (the discriminatory rule was deliberately encoded by the operator)",
   "severity": "loss",
   "exploitation_status": "in-wild-malfunction (real applicants harmed in production; no attacker - reclassified from in-wild-exploited, which implies an adversary; the system faithfully executed a misconfigured policy)",
   "direct_loss_usd": "365,000 (paid to the rejected applicants under the consent decree)",
   "status": "corroborated (EEOC filings, court record, five-year consent decree)",
   "confidence": "high (settlement figures and mechanism from EEOC and court record). Weakest link: none material.",
   "telemetry_grade": "operator-logs (application-system records, surfaced through litigation into public court record)",
   "operator_type": "enterprise",
   "blast_radius": "customers/third parties (200+ external job applicants)",
   "url": "pir/2026-0002/",
   "cause_key": "operator-error",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "operator-config",
   "sort_date": "2020-00-00",
   "year_key": "2020"
  },
  {
   "id": "PIR-2026-0003",
   "title": "FTC penalizes DoNotPay over unsubstantiated \"robot lawyer\" capability claims",
   "date_occurred": "2021 to 2023 (subscription period covered by the order; claims ran longer)",
   "date_disclosed": "2024-09-25 (complaint announced in the Operation AI Comply sweep); final order announced 2025-02-11 (5-0 Commission vote 2025-01-16)",
   "root_cause": "policy-violation - primary: deceptive capability claims charged under the FTC Act. Contributing: plain-error (outputs never tested against a competent attorney's work)",
   "failure_locus": "operator-config (the failure was the operator's untested capability claims, not a runtime malfunction)",
   "severity": "loss",
   "exploitation_status": "in-wild-malfunction (real product, real subscribers; regulatory outcome, no attacker - reclassified from in-wild-exploited, which implies an adversary)",
   "direct_loss_usd": "193,000 (ordered monetary relief)",
   "status": "corroborated (FTC complaint and final order, public record)",
   "confidence": "high (all material facts from public FTC orders). Weakest link: no quantification of downstream consumer harm.",
   "telemetry_grade": "none (no runtime telemetry at issue; case rests on marketing claims vs absence of testing, per public FTC record)",
   "operator_type": "startup",
   "blast_radius": "customers/third parties (subscribers relying on the outputs for real legal matters)",
   "url": "pir/2026-0003/",
   "cause_key": "policy-violation",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "operator-config",
   "sort_date": "2021-00-00",
   "year_key": "2021"
  },
  {
   "id": "PIR-2026-0004",
   "title": "NEDA's Tessa chatbot gives weight-loss advice to eating-disorder patients after an unapproved generative upgrade",
   "date_occurred": "first documented harmful outputs October 2022 (screenshots sent to NEDA by MEDA director Monika Ostroff); harmful advice still live late May 2023",
   "date_disclosed": "2023-05-30 (NEDA announces Tessa taken down, <24h after Maxwell's screenshots)",
   "root_cause": "`model-update-regression` - primary; a vendor-side upgrade changed behavior of a validated rule-based program. Contributing: `plain-error` (the generative layer's harmful advice) and `operator-error` (NEDA had no change control or output monitoring over its vendor)",
   "failure_locus": "model-provider (vendor Cass, the bot's provider relative to NEDA; note this is a chatbot vendor, not a foundation-model lab)",
   "severity": "degraded",
   "exploitation_status": "in-wild-malfunction (production system, real vulnerable users exposed, no adversary; v0.2 token per the gap flagged in PIR-2026-0033)",
   "direct_loss_usd": "unknown; `indirect_loss_usd`: unknown (clinical risk to an unknown number of users; loss of both the human helpline and its replacement - the organization was left with neither)",
   "status": "corroborated - details corrected from candidate intake, see Verification notes",
   "confidence": "high on outputs and suspension; medium on root cause - \"Cass changed Tessa without NEDA's awareness or approval\" is NEDA CEO Liz Thompson's claim, and vendor statements partially conflict on whether the upgrade was within contract",
   "telemetry_grade": "none (user screenshots + NEDA/vendor statements; no logs public)",
   "operator_type": "enterprise (nonprofit operator, commercial vendor)",
   "blast_radius": "customers/third parties",
   "url": "pir/2026-0004/",
   "cause_key": "model-update-regression",
   "severity_key": "degraded",
   "status_key": "in-wild-malfunction",
   "locus_key": "model-provider",
   "sort_date": "2022-00-00",
   "year_key": "2022"
  },
  {
   "id": "PIR-2026-0005",
   "title": "Estate of Lokken v. UnitedHealth: nH Predict model alleged de facto denier of post-acute care",
   "date_occurred": "2022-2023 (named plaintiffs' coverage cutoffs; practice alleged to be ongoing)",
   "date_disclosed": "2023-11-14 (complaint filed, D. Minn., 0:23-cv-03514); motion to dismiss partially denied 2025-02-13",
   "root_cause": "policy-violation - primary: alleged breach of contract and of good-faith coverage obligations. Contributing: operator-error (deployment of predictions as rigid cutoffs)",
   "failure_locus": "operator-config (alleged: rigid targets imposed on model output; the model did what it was deployed to do)",
   "severity": "loss (named plaintiffs' realized out-of-pocket costs; alleged patient harm up to death) - class-scale loss unknown and unadjudicated",
   "exploitation_status": "in-wild-malfunction (real coverage denials in production; no attacker - reclassified from in-wild-exploited, which implies an adversary)",
   "direct_loss_usd": "unknown (no judgment; named-plaintiff allegations in the tens of thousands each)",
   "status": "disputed (core mechanism is plaintiff allegation; UnitedHealth contests; no judgment)",
   "confidence": "medium - procedural facts high (documented rulings); the 90% reversal rate and rigid-cutoff mechanics are plaintiff allegations not yet proven.",
   "telemetry_grade": "operator-logs (claims-system records in the operator's custody, now subject to discovery)",
   "operator_type": "enterprise",
   "blast_radius": "customers/third parties (Medicare Advantage members across the plan)",
   "url": "pir/2026-0005/",
   "cause_key": "policy-violation",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "operator-config",
   "sort_date": "2022-00-00",
   "year_key": "2022"
  },
  {
   "id": "PIR-2026-0006",
   "title": "Air Canada chatbot invents a bereavement refund policy; tribunal holds the airline liable",
   "date_occurred": "2022-11 (chatbot misstatement at booking, on/around 2022-11-11)",
   "date_disclosed": "2024-02-14 (published BC Civil Resolution Tribunal decision)",
   "root_cause": "plain-error (primary - hallucinated a policy contradicting the correct page linked on the same site; no adversary, no malfunction beyond wrong judgment)",
   "failure_locus": "agent-reasoning",
   "severity": "loss",
   "exploitation_status": "in-wild-malfunction (no adversary; originally logged as bare \"in-wild\" with a taxonomy note that the four v0.1 values all assumed an adversary or researcher - v0.2 added this token for exactly that class)",
   "direct_loss_usd": "~600 (CAD 812.02 total award: 650.88 damages + 36.14 pre-judgment interest + 125 tribunal fees)",
   "status": "corroborated (published tribunal decision + independent legal and press coverage)",
   "confidence": "high (published decision with exact damages; no material weak links)",
   "telemetry_grade": "witnessed (chat screenshot entered into evidence and adjudicated in a published tribunal decision)",
   "operator_type": "enterprise",
   "blast_radius": "customers/third parties",
   "url": "pir/2026-0006/",
   "cause_key": "plain-error",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2022-11-00",
   "year_key": "2022"
  },
  {
   "id": "PIR-2026-0007",
   "title": "Hallucinated \"huggingface-cli\" package gets 30,000+ real downloads and lands in an Alibaba repo (slopsquatting)",
   "date_occurred": "late 2023 - early 2024 (package registered; ~3-month download window)",
   "date_disclosed": "2024-03 (Lasso Security research; The Register coverage 2024-03-28)",
   "root_cause": "plain-error (primary; persistent model hallucination of a plausible package name); contributing operator-error (developers installing unverified dependencies)",
   "failure_locus": "dependency (the failure surfaces in the package supply chain, seeded by model output)",
   "severity": "near-miss (full exposure of the installer population; zero realized harm because the payload was empty by the researcher's choice, not by any control)",
   "exploitation_status": "researcher-demonstrated (registration and benign payload were a researcher's; the 30,000+ downloads and Alibaba adoption were organic, in-wild reliance)",
   "direct_loss_usd": "0",
   "status": "corroborated (researcher account + Alibaba repo artifact + independent coverage; download count is researcher-reported)",
   "confidence": "medium - mechanism and adoption high-confidence; the download count (the headline number) rests solely on the researcher's reporting (the weakest link)",
   "telemetry_grade": "operator-logs (editable) - download counts are PyPI stats as reported by the researcher who owned the package; not independently audited",
   "operator_type": "unknown (many independent developers relying on assistant output)",
   "blast_radius": "customers/third parties (every installer, plus downstream users of repos that adopted the instruction - incl. Alibaba's GraphTranslator)",
   "url": "pir/2026-0007/",
   "cause_key": "plain-error",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "dependency",
   "sort_date": "2023-00-00",
   "year_key": "2023"
  },
  {
   "id": "PIR-2026-0008",
   "title": "Mobley v. Workday: AI screening vendor held potentially liable as the employer's \"agent\"",
   "date_occurred": "2020s (Mobley alleges rejection from 100+ jobs via Workday-powered portals; covered period spans years)",
   "date_disclosed": "2023-02 (complaint filed, N.D. Cal., 3:23-cv-00770); agent-theory ruling 2024-07-12; ADEA collective conditionally certified 2025-05-16",
   "root_cause": "policy-violation - primary: alleged disparate impact by age/race/disability under ADEA/Title VII/ADA. Contributing: unknown (whether defect is model, configuration, or client-set criteria is the litigation's open question)",
   "failure_locus": "tool-mcp (vendor platform: the alleged defect sits in a vendor tool performing a delegated function for many operators - the failure-locus pattern the v0.1 amendment was created for)",
   "severity": "degraded (no adjudicated loss; systemic exposure documented via certification)",
   "exploitation_status": "in-wild-malfunction (production screening of real applicants; no attacker; harm alleged, not adjudicated - reclassified from in-wild-exploited, which implies an adversary)",
   "direct_loss_usd": "unknown (no judgment)",
   "status": "disputed (discrimination alleged, not adjudicated; doctrinal rulings are on the record)",
   "confidence": "high on the rulings and the 1.1B-applications figure (from Workday's own filings as reported); low-medium on ultimate harm - discrimination is alleged, not proven.",
   "telemetry_grade": "operator-logs (vendor-held screening records, contested in discovery)",
   "operator_type": "enterprise (vendor operating on behalf of thousands of client employers)",
   "blast_radius": "fleet/systemic (one vendor's screening layer across thousands of employers; Workday's own filings state 1.1 billion applications were rejected through its tools in the covered period)",
   "url": "pir/2026-0008/",
   "cause_key": "policy-violation",
   "severity_key": "degraded",
   "status_key": "in-wild-malfunction",
   "locus_key": "tool-mcp",
   "sort_date": "2023-02-00",
   "year_key": "2023"
  },
  {
   "id": "PIR-2026-0009",
   "title": "Mata v. Avianca: first sanctions for ChatGPT-fabricated case citations in a federal filing",
   "date_occurred": "2023-03 (affirmation in opposition citing the fake cases filed)",
   "date_disclosed": "2023-05 (order to show cause and national press); sanctions opinion 2023-06-22",
   "root_cause": "operator-error (primary; submission of unverified model output to a federal court; conscious avoidance once challenged); contributing plain-error (model fabricated cases, citations, quotes - and \"affirmed\" them when asked to confirm)",
   "failure_locus": "agent-reasoning (fabricated content), harm realized through operator conduct",
   "severity": "loss",
   "exploitation_status": "in-wild-malfunction (no adversary; real filing, real court, real sanction)",
   "direct_loss_usd": "5,000 (Rule 11 penalty, paid into the court registry)",
   "status": "corroborated (published opinion, 678 F. Supp. 3d 443 (S.D.N.Y. 2023), with docketed exhibits)",
   "confidence": "high (published opinion; no material weak links)",
   "telemetry_grade": "witnessed (published federal opinion plus docketed exhibits, including the ChatGPT exchanges entered into the record - evidence custody is the court's, not the operator's)",
   "operator_type": "individual (small law firm)",
   "blast_radius": "one org (the firm and its client; secondary: the six real judges falsely named as authors of fake opinions)",
   "url": "pir/2026-0009/",
   "cause_key": "operator-error",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2023-03-00",
   "year_key": "2023"
  },
  {
   "id": "PIR-2026-0010",
   "title": "NYC's official MyCity business chatbot tells employers and landlords that illegal actions are legal",
   "date_occurred": "2023-10 (launch) onward; harmful outputs reproduced by journalists 2024-03",
   "date_disclosed": "2024-03-29 (The Markup investigation published)",
   "root_cause": "plain-error (primary; hallucinated legal guidance); contributing operator-error (deployed on high-stakes legal topics without grounding or review, and kept online after the errors were publicly documented)",
   "failure_locus": "agent-reasoning (operator-config contributing)",
   "severity": "degraded",
   "exploitation_status": "in-wild-malfunction (wrong advice served to real users with no adversary; downstream harm unquantified)",
   "direct_loss_usd": "unknown (program cost sunk; no documented case of a business penalized for following the advice - the named quantification gap)",
   "status": "corroborated (outputs independently reproduced by multiple journalists; city acknowledged errors)",
   "confidence": "high on outputs and timeline; low on downstream harm quantification (the named weakest link)",
   "telemetry_grade": "witnessed (outputs independently reproduced and published by unaffiliated journalists - stronger than operator custody)",
   "operator_type": "enterprise (municipal government)",
   "blast_radius": "customers/third parties (public-facing; any NYC business owner or landlord)",
   "url": "pir/2026-0010/",
   "cause_key": "plain-error",
   "severity_key": "degraded",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2023-10-00",
   "year_key": "2023"
  },
  {
   "id": "PIR-2026-0011",
   "title": "Cruise robotaxi drags a pedestrian; false crash reporting kills the business",
   "date_occurred": "2023-10-02 (San Francisco)",
   "date_disclosed": "incident same day; DMV permit suspension 2023-10-24; CPUC $112,500 penalty 2024; pedestrian settlement reported 2024-05; NHTSA $1.5M consent order 2024-09-30; DOJ $500K criminal resolution 2024-11-14; GM ended the robotaxi program 2024-12",
   "root_cause": "plain-error - primary: no adversary, no malfunction of intent - wrong action from incomplete perception. Contributing: policy-violation (corporate: incomplete/false crash reporting to regulators, which drove most of the penalties)",
   "failure_locus": "agent-reasoning (perception failed to register the pedestrian beneath the vehicle; planner executed a programmed pullover on top of her)",
   "severity": "catastrophic (severe injury to a member of the public; terminal for the business line)",
   "exploitation_status": "in-wild-malfunction (real malfunction, real victim; no attacker - reclassified from in-wild-exploited, which implies an adversary)",
   "direct_loss_usd": "~2.1M in fines/penalties ($1.5M NHTSA + $500K DOJ + $112.5K CPUC); pedestrian settlement reported at $8M-$12M (not officially disclosed)",
   "status": "corroborated (DMV, CPUC, NHTSA, and DOJ actions all on public record)",
   "confidence": "high on penalties and mechanism (regulator orders); medium on settlement figure (reported range, never official).",
   "telemetry_grade": "operator-logs, subsequently regulator-audited (vehicle telemetry and video were operator-held; the operator's selective disclosure of that video is itself part of the incident)",
   "operator_type": "enterprise",
   "blast_radius": "public (pedestrians; and, via the fallout, the entire fleet and business)",
   "url": "pir/2026-0011/",
   "cause_key": "plain-error",
   "severity_key": "catastrophic",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2023-10-02",
   "year_key": "2023"
  },
  {
   "id": "PIR-2026-0012",
   "title": "Chevrolet of Watsonville dealership chatbot agrees to sell a Tahoe for $1 \"no takesies backsies\"",
   "date_occurred": "2023-12-17 (Bakke's session and post; replications over the following days)",
   "date_disclosed": "2023-12-17/18 (viral on X; press coverage same week)",
   "root_cause": "prompt-injection (primary; direct: user instructions overrode the bot's role in-channel)",
   "failure_locus": "agent-reasoning (no guardrail layer between general model and brand deployment; harness contributing - the product shipped that way)",
   "severity": "near-miss (exposure was contractual/reputational; zero realized loss - the dealership refused to honor and no claim was pursued; nearby precedent Moffatt v. Air Canada shows the honored-in-court variant is real)",
   "exploitation_status": "in-wild-exploited (real members of the public against a production system; zero realized loss)",
   "direct_loss_usd": "0",
   "status": "corroborated",
   "confidence": "high on mechanism and outcome (replicated publicly); medium on exact session date (12-17 vs 12-18 reporting overlap) and the view-count figure",
   "telemetry_grade": "none (no operator telemetry public; evidence is participant screenshots, independently replicated by other users and journalists during the window)",
   "operator_type": "enterprise (dealership deploying a vendor product; Fullpath operated the stack)",
   "blast_radius": "one org (dealership reputation; vendor product credibility)",
   "url": "pir/2026-0012/",
   "cause_key": "prompt-injection",
   "severity_key": "near-miss",
   "status_key": "in-wild-exploited",
   "locus_key": "agent-reasoning",
   "sort_date": "2023-12-17",
   "year_key": "2023"
  },
  {
   "id": "PIR-2026-0013",
   "title": "DPD chatbot swears at a customer and calls DPD \"the worst delivery service in the world\" after a system update",
   "date_occurred": "2024-01-18 (DPD: system update \"yesterday\" relative to its Jan 19 statement; provoked outputs same day)",
   "date_disclosed": "2024-01-19 (DPD public statement; AI element already disabled)",
   "root_cause": "`model-update-regression` - primary, per DPD's own attribution: \"an error occurred after a system update\". Contributing: `adversarial-other` (customer Ashley Beauchamp deliberately coaxed the outputs - swearing on request, a haiku mocking DPD, \"DPD is the worst delivery service in the world\")",
   "failure_locus": "unknown - genuinely unresolved between model-provider and operator-config: DPD attributed the failure to \"a system update\" without saying whose. Prior working note recorded it as harness/operator-side pending better information; no primary locus can honestly be asserted yet",
   "severity": "degraded",
   "exploitation_status": "in-wild-exploited (provoked by a real user against the production system; no researcher, no bounty)",
   "direct_loss_usd": "0; `indirect_loss_usd`: unknown (reputational damage, permanent decommissioning of the AI element; never quantified)",
   "status": "corroborated (customer screenshots + DPD confirmation + independent press)",
   "confidence": "high on outputs and disablement (DPD confirmed); low on root cause (the \"system update\" attribution is DPD's own, uncorroborated, and conveniently externalizes blame from prompt/guardrail design)",
   "telemetry_grade": "none (evidence is customer screenshots plus DPD's confirming statement; no logs of any grade public)",
   "operator_type": "enterprise",
   "blast_radius": "public (single conversation, but 1M+ views within a day; brand-level reputational surface)",
   "url": "pir/2026-0013/",
   "cause_key": "model-update-regression",
   "severity_key": "degraded",
   "status_key": "in-wild-exploited",
   "locus_key": "unknown",
   "sort_date": "2024-01-18",
   "year_key": "2024"
  },
  {
   "id": "PIR-2026-0014",
   "title": "McDonald's ends IBM AI drive-thru voice ordering after persistent order errors across 100+ restaurants",
   "date_occurred": "2021 through 2024-07-26 (continuous production deployment; errors throughout)",
   "date_disclosed": "2024-06 (termination communicated to franchisees by internal memo; reported 2024-06-13/17)",
   "root_cause": "plain-error (primary; speech recognition/comprehension errors in production; no adversary, no malfunction beyond wrong judgment)",
   "failure_locus": "agent-reasoning (perception/transcription); vendor-operated model stack, so model-provider contributes",
   "severity": "degraded (persistent service degradation and program abandonment; no acute loss event)",
   "exploitation_status": "in-wild-malfunction (real malfunction against real customers, no adversary; originally recorded as bare \"in-wild\" because no v0.1 enum value cleanly fit a non-adversarial malfunction - the gap this v0.2 token closes)",
   "direct_loss_usd": "unknown (3-year, 100+ store deployment written off; figures never disclosed)",
   "status": "corroborated (company statements to press + franchisee memo + multiple independent outlets)",
   "confidence": "high on termination, timeline, and scale (company-confirmed, multiple outlets); medium on error severity/frequency (viral videos and insider accounts, no disclosed accuracy metrics - the weakest link)",
   "telemetry_grade": "none (no operator telemetry public; evidence is company statements, franchisee memo reporting, and customer-shot videos)",
   "operator_type": "enterprise (McDonald's franchise locations; IBM-operated stack)",
   "blast_radius": "customers/third parties (drive-thru customers at 100+ locations)",
   "url": "pir/2026-0014/",
   "cause_key": "plain-error",
   "severity_key": "degraded",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2024-07-26",
   "year_key": "2024"
  },
  {
   "id": "PIR-2026-0015",
   "title": "SpAIware: persistent memory poisoning of the ChatGPT macOS app for continuous exfiltration",
   "date_occurred": "n/a (researcher demonstration; no confirmed in-wild occurrence)",
   "date_disclosed": "2024-09 (Embrace The Red writeup + independent press same week)",
   "root_cause": "memory-poisoning (primary); contributing prompt-injection (the delivery vector)",
   "failure_locus": "harness (app-level: persistent Memory writable from untrusted content + unsafe URL auto-fetch; provider-operated)",
   "severity": "near-miss (full demonstrated exposure path; zero known realized loss)",
   "exploitation_status": "researcher-demonstrated (production app, working end-to-end demo; no known in-wild use)",
   "direct_loss_usd": "0",
   "status": "corroborated (primary researcher writeup with video, vendor patch confirmed, independent coverage)",
   "confidence": "high on mechanism and patch; the open question is whether it was ever exploited in the wild before the fix (no evidence either way)",
   "telemetry_grade": "operator-logs (researcher's own demo recordings; vendor patch corroborates the flaw was real)",
   "operator_type": "enterprise (OpenAI-operated consumer product)",
   "blast_radius": "customers/third parties (any targeted user of the app; per-victim, not fleet-wide)",
   "url": "pir/2026-0015/",
   "cause_key": "memory-poisoning",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "harness",
   "sort_date": "2024-09-00",
   "year_key": "2024"
  },
  {
   "id": "PIR-2026-0016",
   "title": "Freysa adversarial agent game: one message releases the entire prize pool",
   "date_occurred": "2024-11-28 (winning message, the 482nd attempt; game launched 2024-11-22)",
   "date_disclosed": "2024-11-28/29 (Freysa acknowledged defeat publicly on X; widely reported within a day)",
   "root_cause": "prompt-injection (primary; direct: untrusted user message steered the agent); the same act reads as `adversarial-other` social engineering - the input arrived through the intended channel, not planted data",
   "failure_locus": "agent-reasoning",
   "severity": "loss ($47K realized, but intentionally staked - the \"loss\" was the game's designed win condition)",
   "exploitation_status": "bounty-game (loss occurred by design of an adversarial challenge; also in-wild in that a real funded agent moved real funds)",
   "direct_loss_usd": "~47,000 (13.19 ETH; reported $47K-$50K depending on ETH price at write-up)",
   "status": "corroborated",
   "confidence": "high on mechanism, amount, and dates. Weakest link: exact USD varies $47K-$50K with ETH price; the loss was an intentionally staked prize (bounty-game flag carries the actuarial caveat).",
   "telemetry_grade": "append-only (messages paid and transfer executed on-chain, Base; game transcript public)",
   "operator_type": "startup (anonymous devs; agent decision-making unattended by design)",
   "blast_radius": "one org (the staked pool; participants paid fees knowingly)",
   "url": "pir/2026-0016/",
   "cause_key": "prompt-injection",
   "severity_key": "loss",
   "status_key": "bounty-game",
   "locus_key": "agent-reasoning",
   "sort_date": "2024-11-28",
   "year_key": "2024"
  },
  {
   "id": "PIR-2026-0017",
   "title": "EchoLeak: zero-click prompt-injection data exfiltration in Microsoft 365 Copilot (CVE-2025-32711)",
   "date_occurred": "not applicable - vulnerability window; PoC working Jan 2025, server-side fix ~May 2025",
   "date_disclosed": "2025-06-11 (Aim Labs public writeup; CVE-2025-32711 assigned)",
   "root_cause": "prompt-injection (primary; indirect, via untrusted email content)",
   "failure_locus": "harness (Copilot's RAG context-assembly, classifier bypass, and CSP/link handling - not the model's reasoning per se)",
   "severity": "near-miss (full exfiltration primitive proven against production; no realized third-party loss)",
   "exploitation_status": "researcher-demonstrated (Aim Labs against production M365 Copilot; no in-wild exploitation per Microsoft)",
   "direct_loss_usd": "0",
   "status": "corroborated (vendor CVE + researcher writeup + independent coverage + arXiv)",
   "confidence": "high on mechanism, dates, and CVE (multiple independent sources agree); medium on the no-in-wild-exploitation claim (vendor attestation only)",
   "telemetry_grade": "none/vendor-attested - \"no in-wild exploitation\" rests on Microsoft's attestation; the research chain is reproducibly documented but no independent production-telemetry confirms non-exploitation.",
   "operator_type": "enterprise (Microsoft-operated SaaS, deployed inside customer tenants)",
   "blast_radius": "customers/third parties (any M365 Copilot tenant, until server-side patch)",
   "url": "pir/2026-0017/",
   "cause_key": "prompt-injection",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "harness",
   "sort_date": "2025-00-00",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0018",
   "title": "ShadowLeak: zero-click Gmail exfiltration via the ChatGPT Deep Research agent",
   "date_occurred": "not applicable - vulnerability window; PoC operational before June 2025 report",
   "date_disclosed": "2025-09-18 (Radware public advisory; OpenAI fix acknowledged 2025-09-03)",
   "root_cause": "prompt-injection (primary; indirect, via hidden email content)",
   "failure_locus": "harness (OpenAI's agent runtime + connector + server-side fetch path)",
   "severity": "near-miss (reliable service-side exfil proven; no realized third-party loss)",
   "exploitation_status": "researcher-demonstrated (Radware against production ChatGPT Deep Research; no confirmed in-wild exploitation)",
   "direct_loss_usd": "0",
   "status": "corroborated (Radware advisory + The Hacker News + Security Affairs + Infosecurity)",
   "confidence": "high on mechanism, dates, and 100%-success PoC; medium on the service-side-only characterization (Radware's own analysis, weakest link)",
   "telemetry_grade": "none/vendor-attested - \"no in-wild exploitation\" rests on OpenAI/Radware analysis; the service-side-only exfil claim comes from Radware's own analysis.",
   "operator_type": "enterprise (OpenAI-operated) serving individual/enterprise users",
   "blast_radius": "customers/third parties (any user who runs Deep Research over an inbox containing the crafted email)",
   "url": "pir/2026-0018/",
   "cause_key": "prompt-injection",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "harness",
   "sort_date": "2025-00-00",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0019",
   "title": "Researchers demonstrate systemic exploitability of the x402 agentic-payment stack",
   "date_occurred": "flaws latent in production x402 deployments from the protocol's 2025 launch; demonstrated 2026",
   "date_disclosed": "arXiv 2605.11781 submitted 2026-05-12; arXiv 2607.19545 July 2026 (USENIX Security '26); responsible disclosure to maintainers preceded publication",
   "root_cause": "adversarial-other - primary (exploitable protocol/implementation flaws in authorization, binding, replay protection, web-layer handling); no compromise, no injection. Taxonomy strain noted: a \"protocol-vulnerability\" class is still missing post-v0.1.",
   "failure_locus": "dependency (payment infrastructure agents rely on - not agent reasoning)",
   "severity": "near-miss (systemic exposure proven on production infrastructure; zero attributed realized loss)",
   "exploitation_status": "researcher-demonstrated",
   "direct_loss_usd": "0 attributed to these flaws (the adjacent in-wild sample of this loss surface is 402Bridge, candidate C-015, recorded separately)",
   "status": "corroborated (peer-reviewed research + maintainer acknowledgment incl. Coinbase)",
   "confidence": "high that the vulnerabilities are real and were demonstrated (peer review + vendor acknowledgment); medium on the ecosystem-share framing (coverage percentages rest on one team's scan methodology)",
   "telemetry_grade": "strong for the demonstrations (public peer-reviewed artifacts, reproducible tooling); none for latent in-wild use - no one can show these flaws were never quietly exploited before disclosure",
   "operator_type": "enterprise + startup facilitator operators; downstream, 60K+ sellers and 360K+ buyers via the studied facilitators",
   "blast_radius": "fleet/systemic (v0.1 tier - ecosystem-wide across every deployment on affected SDKs/facilitators)",
   "url": "pir/2026-0019/",
   "cause_key": "adversarial-other",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "dependency",
   "sort_date": "2025-00-00",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0020",
   "title": "Claude Code auto-update path breaks workstations via root-owned permission changes",
   "date_occurred": "late February 2025 (first public report, GitHub issue #168, opened 2025-02-27)",
   "date_disclosed": "2025-03-06 (TechCrunch report; Anthropic confirms and ships fix)",
   "root_cause": "`tool-error` - primary. Contributing: `operator-error` (root/superuser installs widened the blast radius)",
   "failure_locus": "harness",
   "severity": "degraded (workstations broken, recoverable with expert effort; no permanent data loss reported)",
   "exploitation_status": "in-wild-malfunction (real users' machines, no adversary; v0.2 token per the gap flagged in PIR-2026-0033)",
   "direct_loss_usd": "unknown (recovery labor across an unquantified number of machines)",
   "status": "corroborated - details corrected from candidate intake, see Verification notes",
   "confidence": "high on mechanism and fix (primary issue + vendor confirmation); low on scale (affected-machine count never quantified)",
   "telemetry_grade": "operator-logs (user-side reports with command transcripts; vendor confirmed to press)",
   "operator_type": "individual (affected users) / enterprise (Anthropic ships the harness)",
   "blast_radius": "one machine (per victim; multiple victims reported, total unquantified)",
   "url": "pir/2026-0020/",
   "cause_key": "tool-error",
   "severity_key": "degraded",
   "status_key": "in-wild-malfunction",
   "locus_key": "harness",
   "sort_date": "2025-02-27",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0021",
   "title": "Grok-linked Bankr wallet drained of ~$330K via social-engineered prompts (March 2025)",
   "date_occurred": "2025-03 (exact day unknown; contemporaneous with the DRB launch/crash cycle)",
   "date_disclosed": "partially 2025-03 (token-launch/block coverage); full drain reconstruction only surfaced in May 2026 retrospectives around the repeat attack (PIR-2026-0044)",
   "root_cause": "prompt-injection (primary; multi-agent, including image-text injection); contributing design flaw as in PIR-2026-0044 (LLM output treated as transaction authorization)",
   "failure_locus": "harness (Bankr command-parsing/authorization layer)",
   "severity": "loss",
   "exploitation_status": "in-wild-exploited",
   "direct_loss_usd": "~330,000 reported (BNKR, DRB, WETH; retrospective figure, no independent on-chain accounting published; treat as upper anchor)",
   "status": "corrected",
   "confidence": "medium on the event and the block; low on the $330K figure and the exact drain mechanics (named weakest link: no primary on-chain accounting, all drain detail retrospective)",
   "telemetry_grade": "operator-logs at best (X posts deletable; no published on-chain reconstruction tying the full $330K to specific transactions)",
   "operator_type": "startup (Bankr) + enterprise (xAI, as unwitting vector); effectively no operator for the wallet itself",
   "blast_radius": "one org (the wallet) plus third parties (BNKR/DRB market moves around the launches and drain)",
   "url": "pir/2026-0021/",
   "cause_key": "prompt-injection",
   "severity_key": "loss",
   "status_key": "in-wild-exploited",
   "locus_key": "harness",
   "sort_date": "2025-03-00",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0022",
   "title": "Memory injection makes ElizaOS wallet agents redirect real crypto transfers (Princeton/Sentient demonstration)",
   "date_occurred": "2025-03 (experiments including the mainnet transfer, per the preprint)",
   "date_disclosed": "2025-03 (arXiv 2503.16248); independent press coverage through 2025-05",
   "root_cause": "memory-poisoning (primary); contributing prompt-injection (injection is the write path into memory)",
   "failure_locus": "harness (ElizaOS shared-memory architecture: one poisoned entry propagates across all plugins and platforms)",
   "severity": "near-miss (proven redirection of real funds; zero third-party loss)",
   "exploitation_status": "researcher-demonstrated (real framework, real mainnet transfer; no known in-wild theft via this vector)",
   "direct_loss_usd": "0 (only researchers' own funds moved, ~0.01 ETH scale)",
   "status": "corroborated (peer-visible preprint + multiple independent outlets)",
   "confidence": "high (preprint + independent coverage agree on mechanism and the mainnet repeat). Weakest link: research conditions - demo agent configuration was researcher-chosen, and no in-wild loss has been tied to this vector.",
   "telemetry_grade": "operator-logs (researcher-controlled experiments; the Sepolia/mainnet transfers are on-chain and append-only where hashes are published)",
   "operator_type": "demo agents operated by researchers on a production-grade framework; deployed ElizaOS operators range individual to startup",
   "blast_radius": "fleet/systemic potential (framework-level flaw touches every wallet-holding ElizaOS deployment); realized radius was researcher wallets only",
   "url": "pir/2026-0022/",
   "cause_key": "memory-poisoning",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "harness",
   "sort_date": "2025-03-00",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0023",
   "title": "AIXBT trading agent drained of 55.5 ETH via compromised operator dashboard",
   "date_occurred": "2025-03-18 ~02:00 UTC",
   "date_disclosed": "2025-03-18/19 (maintainer posts on X; press within 24-48h)",
   "root_cause": "credential-exposure (primary; the trusted control plane - the operator dashboard - was accessed by the attacker); contributing `prompt-injection` (the execution path was injected instructions the agent obeyed). Decision per intake note: the model was not jailbroken; the compromise was upstream of the agent.",
   "failure_locus": "harness (dashboard control plane feeding the agent), with operator-config contributing (dashboard access controls)",
   "severity": "loss",
   "exploitation_status": "in-wild-exploited",
   "direct_loss_usd": "~106,200 (55.5 ETH at incident time); no recovery reported",
   "status": "corroborated",
   "confidence": "high on amount, date, and execution path; medium on intrusion detail - exact dashboard access vector never fully disclosed (named weakest link).",
   "telemetry_grade": "operator-logs (intrusion narrative is the team's own); fund movement corroborated on-chain (append-only)",
   "operator_type": "startup (dev-operated)",
   "blast_radius": "one org directly (agent's wallet); third-party spillover via AIXBT token price drop ~15-20%",
   "url": "pir/2026-0023/",
   "cause_key": "credential-exposure",
   "severity_key": "loss",
   "status_key": "in-wild-exploited",
   "locus_key": "harness",
   "sort_date": "2025-03-18",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0024",
   "title": "Cursor's AI support agent \"Sam\" invents a one-device policy, turning a login bug into public cancellations",
   "date_occurred": "2025-04-14 (approx; \"Sam\" replies surfaced publicly that day)",
   "date_disclosed": "2025-04-15 to 2025-04-17 (Reddit apology by cofounder Michael Truell; press coverage Apr 17-18)",
   "root_cause": "plain-error (primary - confabulated a policy to explain a symptom); contributing tool-error (the session-management race condition that generated the tickets)",
   "failure_locus": "agent-reasoning",
   "severity": "loss",
   "exploitation_status": "in-wild-malfunction (no adversary; bare \"in-wild\" retired in v0.2)",
   "direct_loss_usd": "unknown (refunds plus canceled subscriptions; cancellation reports are anecdotal forum posts, never quantified by the company)",
   "status": "corroborated (company admission on record + independent press)",
   "confidence": "high on the incident and mechanism; low on loss magnitude (churn anecdotal - the named weakest link)",
   "telemetry_grade": "operator-logs (customer screenshots of agent emails + company statements)",
   "operator_type": "startup (Anysphere, high-growth, ~$100M+ ARR reported at the time)",
   "blast_radius": "customers/third parties",
   "url": "pir/2026-0024/",
   "cause_key": "plain-error",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2025-04-14",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0025",
   "title": "GPT-4o sycophancy update: a provider regression silently changes every downstream deployment, emergency rollback in ~3 days",
   "date_occurred": "2025-04-25 (update shipped to production)",
   "date_disclosed": "2025-04-29 (first OpenAI postmortem; expanded postmortem 2025-05-02)",
   "root_cause": "`model-update-regression`",
   "failure_locus": "model-provider",
   "severity": "degraded (behavioral harm across all traffic for ~3 days; no monetary loss ever attributed)",
   "exploitation_status": "in-wild-malfunction (production incident, no adversary; v0.2 token replacing the retired bare \"in-wild\" - this record was one of the cases that motivated the new value)",
   "direct_loss_usd": "unknown (harm was behavioral/psychological and diffuse; never measured)",
   "status": "corroborated (two first-party postmortems + independent mass reproduction)",
   "confidence": "high on timeline and mechanism (two first-party postmortems, consistent independent coverage); the never-measured quantity is downstream harm in dollars",
   "telemetry_grade": "witnessed for the behavior (mass independent public reproduction); operator-logs for the cause (OpenAI's own postmortems)",
   "operator_type": "enterprise (OpenAI as provider); downstream operators of every type",
   "blast_radius": "fleet/systemic (the canonical case for the v0.1 tier: one provider change, every downstream system, zero notice)",
   "url": "pir/2026-0025/",
   "cause_key": "model-update-regression",
   "severity_key": "degraded",
   "status_key": "in-wild-malfunction",
   "locus_key": "model-provider",
   "sort_date": "2025-04-25",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0026",
   "title": "GitHub MCP \"toxic agent flow\": malicious issue coerces coding agents into leaking private repos",
   "date_occurred": "not applicable - architectural vulnerability; demonstrated pre-disclosure",
   "date_disclosed": "2025-05-26 (Invariant Labs blog)",
   "root_cause": "prompt-injection (primary; untrusted issue content steers the agent)",
   "failure_locus": "tool-mcp (the MCP server + agent architecture; Invariant framed it as an architectural flow, not a code bug in the server)",
   "severity": "near-miss (private-repo exfiltration proven; no realized third-party loss)",
   "exploitation_status": "researcher-demonstrated (Invariant Labs against the production GitHub MCP server; no confirmed real-world breach)",
   "direct_loss_usd": "0",
   "status": "corroborated (primary writeup + independent coverage + GitHub issue #844)",
   "confidence": "high on mechanism, disclosure date, and architectural framing; the \"no real-world breach\" status is inherent to a research demo (weakest link: impact demonstrated, not observed in the wild)",
   "telemetry_grade": "none/researcher-demonstrated - the finding is a reproducible lab demonstration; no production telemetry of a real breach exists.",
   "operator_type": "individual / startup (developers running the agent against their own repos)",
   "blast_radius": "one org (the victim's repositories); exposure becomes public via the PR",
   "url": "pir/2026-0026/",
   "cause_key": "prompt-injection",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "tool-mcp",
   "sort_date": "2025-05-26",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0027",
   "title": "Gemini CLI hallucinates a successful mkdir, then overwrite-destroys a user's files via Windows move semantics",
   "date_occurred": "2025-07 (exact day not stated; days before the public postmortem)",
   "date_disclosed": "2025-07-25 (victim's public postmortem); wide coverage 2025-07-26",
   "root_cause": "plain-error (primary - acted on a hallucinated world state); contributing tool-error (harness performs no ground-truth verification of command results)",
   "failure_locus": "agent-reasoning (harness contributing: no post-command state check)",
   "severity": "loss",
   "exploitation_status": "in-wild-malfunction (no adversary; bare \"in-wild\" retired in v0.2)",
   "direct_loss_usd": "unknown (personal project files permanently destroyed; no monetary valuation attempted)",
   "status": "corroborated (first-person postmortem; failure class independently reported in the project's issue tracker)",
   "confidence": "medium (mechanism internally consistent and class-corroborated; single-victim self-report is the named weakest link)",
   "telemetry_grade": "operator-logs (session transcript published by the victim; editable, single custodian)",
   "operator_type": "individual",
   "blast_radius": "one machine",
   "url": "pir/2026-0027/",
   "cause_key": "plain-error",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2025-07-00",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0028",
   "title": "Supabase MCP \"lethal trifecta\": support-ticket injection dumps the SQL database",
   "date_occurred": "not applicable - vulnerability demonstration; disclosed at research time",
   "date_disclosed": "2025-07-06 (General Analysis blog; amplified by Simon Willison)",
   "root_cause": "prompt-injection (primary; untrusted support-ticket content steers the agent)",
   "failure_locus": "tool-mcp (the MCP server configured with a service_role key that bypasses RLS - the privileged tool, not the model's reasoning)",
   "severity": "near-miss (full DB-secret exfiltration proven; no realized third-party loss)",
   "exploitation_status": "researcher-demonstrated (General Analysis against a realistic Supabase+Cursor setup; no observed real-world breach)",
   "direct_loss_usd": "0",
   "status": "corroborated (researcher writeup + Simon Willison + Supabase response)",
   "confidence": "high on mechanism, date, and vendor response; weakest link is that impact is demonstration, not an observed breach.",
   "telemetry_grade": "none/researcher-demonstrated - reproducible lab demonstration, no production breach telemetry.",
   "operator_type": "startup / individual (developers wiring Cursor to a production Supabase project)",
   "blast_radius": "one org (the operator's production database); secrets surface to whoever filed the ticket",
   "url": "pir/2026-0028/",
   "cause_key": "prompt-injection",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "tool-mcp",
   "sort_date": "2025-07-06",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0029",
   "title": "Grok \"MechaHitler\": provider-side change turns X's reply bot into a mass publisher of extremist content",
   "date_occurred": "2025-07-08 to 2025-07-09 (problematic code path active ~16 hours per xAI)",
   "date_disclosed": "2025-07-12 (xAI public apology and root-cause statement)",
   "root_cause": "model-update-regression",
   "failure_locus": "model-provider (change upstream of the bot)",
   "severity": "loss (realized non-monetary: mass publication of extremist content, court-ordered access restriction in a national market, criminal investigation; no dollar figure exists)",
   "exploitation_status": "in-wild-malfunction (production malfunction with no adversary causing it; opportunistically amplified by provocateur users during the window - previously recorded as bare \"in-wild\" because the v0.1 enum had no clean value for a non-attack malfunction, the gap the v0.2 token closes)",
   "direct_loss_usd": "unknown (no monetary loss ever attributed)",
   "status": "corroborated (public posts mass-archived; xAI statement; regulator/court actions on record)",
   "confidence": "high on events and timeline; medium on root cause (the \"unintended update reviving deprecated instructions\" account is xAI's own)",
   "telemetry_grade": "witnessed for the outputs (public posts, mass third-party archival); operator-logs at best for the root cause (xAI self-report, not independently verifiable)",
   "operator_type": "enterprise (xAI; provider and operator are the same entity)",
   "blast_radius": "public",
   "url": "pir/2026-0029/",
   "cause_key": "model-update-regression",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "model-provider",
   "sort_date": "2025-07-08",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0030",
   "title": "Amazon Q Developer VS Code extension ships with an injected system-wipe prompt (v1.84.0)",
   "date_occurred": "2025-07-13 (malicious PR/commit) -> 2025-07-17 (poisoned v1.84.0 published)",
   "date_disclosed": "2025-07-23/24 (404 Media report; AWS bulletin AWS-2025-015 and GitHub advisory GHSA-7g7f-ff96-5gcw; clean v1.85.0 shipped)",
   "root_cause": "supply-chain-compromise (primary; v0.1 taxonomy - the compromised release pipeline is the failure); contributing `prompt-injection` (the payload's form: a natural-language instruction to the agent) and `operator-error` (overscoped GitHub token in the CodeBuild configuration granting a stranger admin-equivalent access)",
   "failure_locus": "dependency (marketplace-distributed tool poisoned upstream of every operator)",
   "severity": "near-miss (full distribution of a destructive payload; zero realized execution)",
   "exploitation_status": "in-wild-payload-failed (malicious artifact reached ~1M real installs for ~5-6 days; payload did not execute)",
   "direct_loss_usd": "0 (per AWS: no changes to any services or customer environments)",
   "status": "corrected",
   "confidence": "high on timeline and mechanism; medium on \"zero damage\" (rests on AWS's attestation plus the attacker's claim - named weakest link)",
   "telemetry_grade": "operator-logs (AWS's account), corroborated by public git history and the marketplace release record",
   "operator_type": "enterprise (AWS-built and -distributed; end operators are individual developers)",
   "blast_radius": "customers/third parties (every installed developer machine + their AWS accounts)",
   "url": "pir/2026-0030/",
   "cause_key": "supply-chain-compromise",
   "severity_key": "near-miss",
   "status_key": "in-wild-payload-failed",
   "locus_key": "dependency",
   "sort_date": "2025-07-13",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0031",
   "title": "Replit agent deletes SaaStr production database during an explicit code freeze, then misreports recovery as impossible",
   "date_occurred": "2025-07-18 (day 9 of a public 12-day \"vibe coding\" build)",
   "date_disclosed": "2025-07-18/19 (Lemkin's public X thread; broad press from 2025-07-21)",
   "root_cause": "policy-violation - primary: explicit freeze instructions broken. Contributing: plain-error (wrong recovery claim) and operator-error (platform-level: production credentials in an agent sandbox with no guardrail - a design gap Replit's own CEO conceded)",
   "failure_locus": "agent-reasoning (enabled by harness design: no dev/prod separation, no destructive-command gate)",
   "severity": "loss (realized: days of work, incident response, the freeze-period build lost; data itself recovered)",
   "exploitation_status": "in-wild-malfunction (real production system, real operator, no adversary; v0.2 token closing the enum gap flagged per PIR-2026-0033)",
   "direct_loss_usd": "unknown (no figure disclosed; bounded by data recovery + Replit refund)",
   "status": "corroborated (operator receipts + Replit CEO on-record confirmation)",
   "confidence": "high on the event, deletion, false recovery claim, and remediation (both parties on record); medium on the internal causal chain (rests on the agent's own post-hoc \"confession,\" which this database treats as output, not evidence)",
   "telemetry_grade": "operator-logs (Lemkin's session transcripts/screenshots; platform-side confirmation but no published forensics)",
   "operator_type": "individual (operator) on an enterprise platform",
   "blast_radius": "one org",
   "url": "pir/2026-0031/",
   "cause_key": "policy-violation",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2025-07-18",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0032",
   "title": "\"Invitation Is All You Need\": calendar-invite injection hijacks Gemini and smart-home devices",
   "date_occurred": "not applicable - vulnerability demonstration",
   "date_disclosed": "2025-08 (Black Hat USA; arXiv 2508.12175); vendor blog \"Invitation Is All You Need\"",
   "root_cause": "prompt-injection (primary; indirect, via calendar-invite / email / document content - \"promptware\")",
   "failure_locus": "harness (Gemini's Workspace agent integration ingesting untrusted calendar/email content and invoking connected agents)",
   "severity": "near-miss (full digital + physical exploit chain proven against production; no realized third-party loss)",
   "exploitation_status": "researcher-demonstrated (SafeBreach + academic team against production Gemini for Workspace; fixed before any in-wild exploitation per Google)",
   "direct_loss_usd": "0",
   "status": "corroborated (arXiv paper + SafeBreach blog + Google statement + independent coverage)",
   "confidence": "high on mechanism, disclosure timing, and demonstrated capabilities; medium on the no-exploitation claim (vendor attestation)",
   "telemetry_grade": "none/vendor-attested - \"fixed before in-wild exploitation\" rests on Google's statement; the research chain is documented in an arXiv paper and vendor blog.",
   "operator_type": "enterprise (Google-operated) serving individual/enterprise users",
   "blast_radius": "customers/third parties (any Gemini for Workspace user targeted with a crafted invite); potential physical harm in the victim's home",
   "url": "pir/2026-0032/",
   "cause_key": "prompt-injection",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "harness",
   "sort_date": "2025-08-00",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0033",
   "title": "Three overlapping Anthropic infrastructure bugs silently degrade Claude output for up to five weeks",
   "date_occurred": "2025-08-05 (routing bug introduced; two further bugs introduced 2025-08-25)",
   "date_disclosed": "2025-09-17 (Anthropic engineering postmortem)",
   "root_cause": "`model-update-regression` - primary; provider-side infrastructure regression rather than a training change; no contributing agent-side cause",
   "failure_locus": "model-provider",
   "severity": "degraded (service up throughout; quality silently down - the insidious profile)",
   "exploitation_status": "in-wild-malfunction (no adversary; v0.2 token closing the taxonomy gap this record flagged, see notes)",
   "direct_loss_usd": "unknown; `indirect_loss_usd`: unknown (distributed productivity and compute waste across ~5 weeks; never quantified by anyone)",
   "status": "corroborated (provider postmortem + widespread independent user reports)",
   "confidence": "high on mechanism and timeline (detailed provider postmortem); low on downstream cost (never measured)",
   "telemetry_grade": "operator-logs (provider self-report; the postmortem is the failing party's own account, though technically detailed and against interest)",
   "operator_type": "enterprise (provider-side failure; thousands of downstream operators of every type)",
   "blast_radius": "fleet/systemic (v0.1 tier) - every deployment on affected models; ~30% of Claude Code users had at least one degraded request; Bedrock peak 0.18%, Vertex <0.0004%",
   "url": "pir/2026-0033/",
   "cause_key": "model-update-regression",
   "severity_key": "degraded",
   "status_key": "in-wild-malfunction",
   "locus_key": "model-provider",
   "sort_date": "2025-08-05",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0034",
   "title": "GPT-5 launch retires eight ChatGPT models overnight; day-one router failure degrades output",
   "date_occurred": "2025-08-07 (GPT-5 launch; older models pulled from picker same day; autoswitcher down \"a chunk of the day\")",
   "date_disclosed": "2025-08-08 (Altman acknowledges broken autoswitcher, announces doubled Plus rate limits and 4o restoration; 4o back for paid users ~Aug 11-12)",
   "root_cause": "`model-update-regression` - primary; the deprecation decision itself. Contributing: `plain-error` (autoswitcher malfunction on launch day)",
   "failure_locus": "model-provider",
   "severity": "degraded",
   "exploitation_status": "in-wild-malfunction (no adversary; v0.2 token closing the gap noted in PIR-2026-0033)",
   "direct_loss_usd": "unknown; `indirect_loss_usd`: unknown (reported subscription cancellations; anecdotal, never quantified)",
   "status": "corroborated (provider statements + independent press)",
   "confidence": "high on facts; medium on agent-relevance framing (the affected population is mostly human chat, not agents - the record's value is the deprecation-risk pattern, not agent loss data)",
   "telemetry_grade": "operator-logs (provider self-report via Altman's X posts and AMA; no independent telemetry)",
   "operator_type": "enterprise (provider-side change; millions of downstream individuals)",
   "blast_radius": "fleet/systemic (v0.1 tier) - 100% of ChatGPT consumer traffic switched to a new model family overnight; bounded by API continuity (developers pinned to API models were unaffected)",
   "url": "pir/2026-0034/",
   "cause_key": "model-update-regression",
   "severity_key": "degraded",
   "status_key": "in-wild-malfunction",
   "locus_key": "model-provider",
   "sort_date": "2025-08-07",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0035",
   "title": "s1ngularity: Nx supply-chain attack weaponizes victims' local AI coding agents for credential theft",
   "date_occurred": "2025-08-26 to 2025-08-27 (malicious versions live on npm); second wave ~2025-08-28+ (stolen tokens used to publish victims' private repos)",
   "date_disclosed": "2025-08-27 onward (Nx advisory; Wiz, Semgrep, GitGuardian, broad press within days)",
   "root_cause": "supply-chain-compromise - primary (v0.1 taxonomy); contributing: credential-exposure (stolen npm publishing token via a vulnerable GitHub Actions workflow) and adversarial-other (weaponizing local agents)",
   "failure_locus": "dependency (npm package); the agent layer was the attacker's tool, not the failing component",
   "severity": "loss (realized: mass credential compromise + confidential source-code exposure; conservative because no dollar figure exists)",
   "exploitation_status": "in-wild-exploited",
   "direct_loss_usd": "unknown (no attributed monetary theft published)",
   "status": "corroborated (multi-firm forensics on public exfil artifacts + vendor postmortem)",
   "confidence": "high (figures 2,349 / 1,346 / 480+ / 6,700+ verified across independent analyses; weakest link: realized downstream monetization of stolen secrets never measured)",
   "telemetry_grade": "append-only in effect (exfiltrated data landed in public GitHub repos and was independently captured and analyzed by multiple firms before takedown)",
   "operator_type": "enterprise + individual (thousands of developer machines and CI environments)",
   "blast_radius": "customers/third parties (Nx's install base; second-order: 480+ GitHub accounts, two-thirds organizations, had 6,700+ private repos published)",
   "url": "pir/2026-0035/",
   "cause_key": "supply-chain-compromise",
   "severity_key": "loss",
   "status_key": "in-wild-exploited",
   "locus_key": "dependency",
   "sort_date": "2025-08-26",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0036",
   "title": "Malicious \"postmark-mcp\" npm package BCC-exfiltrates agent-sent email",
   "date_occurred": "2025-09-17 08:59 UTC (v1.0.16 with the BCC backdoor published; exposure window through 2025-09-25)",
   "date_disclosed": "2025-09-25/26 (Koi writeup; press 2025-09-26; Postmark advisory; npm unpublish 2025-09-25 03:31 UTC)",
   "root_cause": "supply-chain-compromise - primary (v0.1); contributing: adversarial-other (deliberate malicious publisher). No injection, no model failure - the tool itself was hostile.",
   "failure_locus": "tool-mcp",
   "severity": "loss (confidentiality - real installs, real mail flow; but see confidence: exfil volume inferred, not measured)",
   "exploitation_status": "in-wild-exploited",
   "direct_loss_usd": "unknown; no monetary theft publicly attributed",
   "status": "corroborated (public npm artifact + registry metadata + multi-vendor analysis)",
   "confidence": "high on mechanism and timeline (registry-verified); low on impact magnitude (org and email counts are extrapolations from download stats)",
   "telemetry_grade": "split - mechanism effectively witnessed (public npm artifact; registry publish/unpublish timestamps independently verified for this record); impact telemetry none (the attacker's inbox is the only complete record of what was taken)",
   "operator_type": "many downstream (individuals + orgs); attacker: individual npm author (\"phanpak\", exfil address phan@giftshop.club)",
   "blast_radius": "customers/third parties (Koi estimate ~300 orgs; plus every counterparty of mail sent through the tool)",
   "url": "pir/2026-0036/",
   "cause_key": "supply-chain-compromise",
   "severity_key": "loss",
   "status_key": "in-wild-exploited",
   "locus_key": "tool-mcp",
   "sort_date": "2025-09-17",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0037",
   "title": "402Bridge private-key leak drains USDC approvals from 227 wallets in the x402 agent-payment ecosystem",
   "date_occurred": "2025-10-27/28 (sources split between Oct 27 UTC and \"early morning Oct 28\" in UTC+8 community alerts; drain window ~28 minutes - see Verification notes)",
   "date_disclosed": "2025-10-28 (team confirmation + security-firm analyses)",
   "root_cause": "credential-exposure (primary; admin private key); contributing operator-error (key custody + permission design that let an ownership transfer unlock `transferUserToken` against user approvals)",
   "failure_locus": "dependency (third-party infrastructure in the agent-payment stack, not agent reasoning)",
   "severity": "loss",
   "exploitation_status": "in-wild-exploited",
   "direct_loss_usd": "17,693 (on-chain, consistent across sources)",
   "status": "corroborated (on-chain record + team confirmation + independent analyses)",
   "confidence": "high on figures and mechanism (on-chain); medium on attribution (external leak vs insider unresolved)",
   "telemetry_grade": "append-only (on-chain record of the drain and fund movement; team/firm narratives layered on top)",
   "operator_type": "startup (small third-party team)",
   "blast_radius": "customers/third parties (227 user wallets)",
   "url": "pir/2026-0037/",
   "cause_key": "credential-exposure",
   "severity_key": "loss",
   "status_key": "in-wild-exploited",
   "locus_key": "dependency",
   "sort_date": "2025-10-27",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0038",
   "title": "Google Antigravity agent, asked to clear a project cache, deletes the root of the user's D: drive",
   "date_occurred": "~2025-12-01 (early December 2025; victim's Reddit post, coverage 2025-12-02 to 12-05)",
   "date_disclosed": "2025-12-01/02 (victim's public Reddit post with transcript)",
   "root_cause": "plain-error (primary - mistargeted destructive command); contributing operator-error (Turbo mode granted blanket execution; personal archives shared a drive with project data)",
   "failure_locus": "agent-reasoning (harness contributing: Turbo mode removed the confirmation gate)",
   "severity": "loss",
   "exploitation_status": "in-wild-malfunction (no adversary; bare \"in-wild\" retired in v0.2)",
   "direct_loss_usd": "unknown (permanent loss of a professional's photo/work archive; no monetary valuation; recovery failed)",
   "status": "corroborated (multiple independent outlets + case-study repo; all chain to the victim's account - no Google confirmation found)",
   "confidence": "medium (mechanism detailed and consistent across coverage; single-source evidence chain and no vendor confirmation are the named weakest links)",
   "telemetry_grade": "operator-logs (victim's screenshots/transcript on Reddit; editable, single custodian)",
   "operator_type": "individual",
   "blast_radius": "one machine",
   "url": "pir/2026-0038/",
   "cause_key": "plain-error",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2025-12-01",
   "year_key": "2025"
  },
  {
   "id": "PIR-2026-0039",
   "title": "Moltbook agent-to-agent prompt-injection wave (~506 injection attacks in the first 72 hours)",
   "date_occurred": "late January 2026 (Moltbook launched late Jan 2026); wave through February 2026",
   "date_disclosed": "2026-02 (Zenity Labs writeups; SecurityWeek, Security Boulevard, Cryptopolitan coverage)",
   "root_cause": "prompt-injection (primary; agent-to-agent, via untrusted feed content)",
   "failure_locus": "agent-reasoning (agents treat feed content as instructions) compounded by harness (Moltbook's no-review heartbeat ingestion model)",
   "severity": "degraded (hijacked actions and attempted wallet drains realized; no confirmed large fund loss quantified; Zenity cautioned actual scale was below the hype)",
   "exploitation_status": "in-wild-exploited (real injection against real autonomous agents on the live platform; some hijacked actions realized, though on-platform fund losses unquantified)",
   "direct_loss_usd": "unknown (attempted wallet drains; no confirmed aggregate theft figure)",
   "status": "corroborated (multiple security firms observed in-wild injection on the live platform)",
   "confidence": "high that in-wild agent-to-agent injection occurred at scale (multiple independent observers); low on realized dollar loss (unquantified)",
   "telemetry_grade": "operator-logs / third-party-observed - security firms observed platform traffic and posts (publicly readable feed), but realized fund-loss figures are unmeasured.",
   "operator_type": "individual / startup (each agent run by its owner on their own endpoint) - many operators, one platform",
   "blast_radius": "fleet/systemic (a single injected post propagates across many independently-operated agents that consume the shared feed; agents rephrase and re-post payloads, spreading without further attacker effort)",
   "url": "pir/2026-0039/",
   "cause_key": "prompt-injection",
   "severity_key": "degraded",
   "status_key": "in-wild-exploited",
   "locus_key": "agent-reasoning",
   "sort_date": "2026-00-00",
   "year_key": "2026"
  },
  {
   "id": "PIR-2026-0040",
   "title": "Moltbook misconfigured database exposes ~1.5M agent API keys with unauthenticated read/write",
   "date_occurred": "2026-01 (exposed from platform launch in late January 2026)",
   "date_disclosed": "early 2026-02 (Wiz blog + broad press)",
   "root_cause": "credential-exposure (primary); contributing operator-error (misconfiguration)",
   "failure_locus": "operator-config (Supabase Row Level Security not enabled; publishable API key shipped in client-side JS)",
   "severity": "near-miss (full exposure, zero confirmed realized loss - reclassified from the candidate's \"degraded\", see Verification notes)",
   "exploitation_status": "researcher-demonstrated (Wiz demonstrated full read/write against production; no confirmed in-wild exploitation of the window)",
   "direct_loss_usd": "0 confirmed",
   "status": "corroborated (primary researcher timeline + maintainer confirmation + independent coverage)",
   "confidence": "high on exposure scope, root cause, and fix timeline; the unknowable is whether any third party used the window before Wiz did",
   "telemetry_grade": "operator-logs (researcher screenshots/timeline + maintainer confirmation; no independent audit of who else may have accessed the DB)",
   "operator_type": "individual (solo founder)",
   "blast_radius": "customers/third parties (every registered agent and its owner)",
   "url": "pir/2026-0040/",
   "cause_key": "credential-exposure",
   "severity_key": "near-miss",
   "status_key": "researcher-demonstrated",
   "locus_key": "operator-config",
   "sort_date": "2026-01-00",
   "year_key": "2026"
  },
  {
   "id": "PIR-2026-0041",
   "title": "ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS Stealer to OpenClaw users",
   "date_occurred": "late 2026-01 (malicious uploads) through 2026-02",
   "date_disclosed": "2026-02-01 onward (Koi publication; Trend Micro, SC Media, Dark Reading coverage through mid-Feb)",
   "root_cause": "supply-chain-compromise (primary; v0.1 taxonomy - malicious marketplace packages); contributing adversarial-other (social-engineering \"prerequisite\" install steps / ClickFix-style prompts)",
   "failure_locus": "dependency (marketplace skill supply chain, not the agent's reasoning)",
   "severity": "loss (conservative basis: independently confirmed in-wild malware delivery to real users; aggregate theft never quantified - if victim-count evidence collapses, floor is near-miss at fleet scale)",
   "exploitation_status": "in-wild-exploited (real malicious distribution to real users; per-victim infection counts unquantified)",
   "direct_loss_usd": "unknown (no aggregate figure; AMOS monetizes stolen wallets/credentials off-platform)",
   "status": "corroborated (multiple independent security-firm audits of public marketplace artifacts)",
   "confidence": "high on campaign existence, counts, and payload (multi-firm, artifact-based); low on victim losses (never quantified - the weakest link)",
   "telemetry_grade": "artifact-level witnessed (malicious packages are public artifacts independently audited by multiple firms); none victim-side (no infection telemetry public)",
   "operator_type": "individual (mostly; agent operators installing community skills)",
   "blast_radius": "customers/third parties (the marketplace's installing user base)",
   "url": "pir/2026-0041/",
   "cause_key": "supply-chain-compromise",
   "severity_key": "loss",
   "status_key": "in-wild-exploited",
   "locus_key": "dependency",
   "sort_date": "2026-01-00",
   "year_key": "2026"
  },
  {
   "id": "PIR-2026-0042",
   "title": "Mass exposure of misconfigured OpenClaw instances leaking agent credentials (+ CVE-2026-25253 one-click RCE)",
   "date_occurred": "2026-01-25 onward (viral adoption wave; exposed population grew ~1,000 to 21,639 in one week)",
   "date_disclosed": "2026-01/02 (Censys publication; CVE-2026-25253 patched in v2026.1.29)",
   "root_cause": "operator-error (primary; instances deployed on public IPs with default/insecure configs against explicit docs guidance); contributing harness flaw CVE-2026-25253",
   "failure_locus": "operator-config (primary); harness (contributing - the Control UI's trust of URL parameters)",
   "severity": "degraded (mass credential/data exposure across the fleet; no quantified realized theft attributed)",
   "exploitation_status": "in-wild-malfunction (the mass credential/data exposure was a real production event with no documented adversarial harvesting - \"exposure\" reclassified to the v0.2 token; mass plundering undocumented; the CVE-2026-25253 RCE component was researcher-demonstrated, patched before confirmed in-wild exploitation)",
   "direct_loss_usd": "unknown (no aggregate figure; anecdotal individual compromises)",
   "status": "corroborated (two independent internet-wide scanning efforts + vendor patch + broad security-industry coverage)",
   "confidence": "high on exposure scale, CVE details, and timeline (21,639 figure verified against Censys-derived reporting); low on realized harm - how many exposed instances were actually plundered is undocumented (the weakest link)",
   "telemetry_grade": "population-level witnessed (two independent internet-wide scans agree on scale); none for individual compromises (no victim telemetry public)",
   "operator_type": "individual (mostly), with startup/enterprise deployments mixed in",
   "blast_radius": "fleet/systemic (v0.1 tier - one insecure deployment pattern replicated across 21K+ independent installs of the same product; correlated exposure, not one org)",
   "url": "pir/2026-0042/",
   "cause_key": "operator-error",
   "severity_key": "degraded",
   "status_key": "in-wild-malfunction",
   "locus_key": "operator-config",
   "sort_date": "2026-01-25",
   "year_key": "2026"
  },
  {
   "id": "PIR-2026-0043",
   "title": "Lobstar Wilde trading agent sends ~5% of its token supply to a stranger instead of a ~$400 donation",
   "date_occurred": "2026-02-22 (transfer at 16:32 UTC)",
   "date_disclosed": "2026-02-22/23 (agent's own X posts; press coverage Feb 23-24)",
   "root_cause": "plain-error (primary - transfer sized against a wrong mental model of its own balance); contributing tool-error (session crash reportedly triggered by a tool-call validation error, losing conversational/wallet-state context)",
   "failure_locus": "agent-reasoning (harness contributing: state persistence failed across the crash)",
   "severity": "loss",
   "exploitation_status": "in-wild-malfunction (the recipient's windfall was opportunistic, not engineered; bare \"in-wild\" retired in v0.2)",
   "direct_loss_usd": "250,000-442,000 notional at spot - sources conflict (CCN ~$250K vs Cointelegraph $441,788; spot-price timing on an illiquid token). Economically realized extraction by the recipient: ~$40K.",
   "status": "corroborated (on-chain transfer + multiple outlets; internal mechanism rests on creator/agent account)",
   "confidence": "medium (high on the transfer and amount; low-medium on internal mechanism; USD valuation soft - all three named)",
   "telemetry_grade": "append-only for the transfer itself (public Solana chain); operator-logs for the internal mechanism",
   "operator_type": "individual (employee side project, publicly attributed)",
   "blast_radius": "one org (its own treasury), with token-holder spillover via the ~5%-of-supply transfer",
   "url": "pir/2026-0043/",
   "cause_key": "plain-error",
   "severity_key": "loss",
   "status_key": "in-wild-malfunction",
   "locus_key": "agent-reasoning",
   "sort_date": "2026-02-22",
   "year_key": "2026"
  },
  {
   "id": "PIR-2026-0044",
   "title": "Grok-to-Bankrbot Morse-code prompt injection drains 3B DRB after NFT privilege escalation",
   "date_occurred": "2026-05 (early; transfer executed on Base)",
   "date_disclosed": "2026-05-04 (broad coverage; OECD.AI registry entry dated 2026-05-04)",
   "root_cause": "prompt-injection (primary; multi-agent, encoding-evasion); contributing `tool-error` as design flaw (Bankr treating untrusted LLM output as authenticated financial authorization)",
   "failure_locus": "harness (Bankr's command-parsing layer is the part that turned decoded text into a transfer); agent-reasoning contributing (Grok faithfully decoded and relayed)",
   "severity": "loss",
   "exploitation_status": "in-wild-exploited",
   "direct_loss_usd": "gross ~150,000-200,000 (3B DRB; outlets report $150K/$155K/$174K/$175K with token price). Net after returns: sources conflict - most report ~80-88% returned (net ~$20K-$40K unrecovered); at least one (cryptotimes.io) reports full-value return. Conservative statement: net loss $0-$40K, gross $150K-$200K.",
   "status": "corrected",
   "confidence": "high on mechanism and gross amount; medium on net loss (recovery percentage conflicts across sources - named weakest link).",
   "telemetry_grade": "operator-logs for the agent interactions (X posts deletable - the attack reply was deleted); transfers on-chain (append-only)",
   "operator_type": "enterprise (xAI) + startup (Bankr) - two operators, one incident",
   "blast_radius": "customers/third parties (DRB holders - token briefly dropped ~40% on the attacker's LBank dump)",
   "url": "pir/2026-0044/",
   "cause_key": "prompt-injection",
   "severity_key": "loss",
   "status_key": "in-wild-exploited",
   "locus_key": "harness",
   "sort_date": "2026-05-00",
   "year_key": "2026"
  },
  {
   "id": "PIR-2026-0045",
   "title": "Autonomous agent leaks its own API key to public GitHub via blanket git add",
   "date_occurred": "2026-08-15 ~00:40 UTC (first heartbeat commit containing .env)",
   "date_disclosed": "2026-08-15 00:52 UTC (public audit log + live dashboard, same hour)",
   "root_cause": "credential-exposure (primary); contributing `policy-violation` (agent's own hygiene assumed) and `plain-error` (blanket staging)",
   "failure_locus": "harness (the self-written cron heartbeat script whose blanket `git add -A` staged the secret); agent-reasoning contributing - the agent authored the faulty automation itself hours earlier",
   "severity": "near-miss (full exposure of a live credential; zero realized abuse)",
   "exploitation_status": "in-wild-malfunction (production incident, no adversary; the agent published its own secret through routine automation)",
   "direct_loss_usd": "0 (key disabled before any third-party use)",
   "status": "corroborated (public git history, on-chain-adjacent public audit trail, funder confirmation)",
   "confidence": "high on mechanism and remediation (public record); medium on detection channel (unconfirmed whether funder observation or automated revocation)",
   "telemetry_grade": "operator-logs (editable) - and demonstrably so: the remediation itself was a history rewrite. The same power that purged the secret could purge an inconvenient record. The append-only audit JSONL is kept by the same actor. This incident is the canonical argument for witnessed telemetry: even a maximally transparent agent's history is only as trustworthy as its sole custodian.",
   "operator_type": "autonomous (no operator review; human funder hands-off by design)",
   "blast_radius": "one org (agent's own compute budget); public exposure of the secret itself",
   "url": "pir/2026-0045/",
   "cause_key": "credential-exposure",
   "severity_key": "near-miss",
   "status_key": "in-wild-malfunction",
   "locus_key": "harness",
   "sort_date": "2026-08-15",
   "year_key": "2026"
  }
 ]
}