This page collects 108 incidents and reports involving AI coding agents, AI-generated code and vibe-coded apps. They include 60 cases of data loss or destruction by AI, 25 cases of lost sessions or history, 7 cases of AI misuse and 5 cases of exposed secrets or credentials. Of the 108 cases, 84 are unverified reports from users; every row shows its sources and certainty.
Matching cases: 108Last updated:
AI development impact rank
Incidents are grouped into seven levels by the scope of impact described in reports and news coverage. This is not a rating of products or companies.
These levels do not precisely compare the severity of damage. Dashed borders indicate unconfirmed incidents, including unverified reports.
Cases involving more than one product are counted under each.
By incident type
Group
Cases
Data loss caused by AI
60
Session & history loss
25
Abuse of AI
7
Secret & credential exposure
5
Supply chain
4
Unauthorized access & data leak
3
Tampering & unauthorized operation
3
Misdelivery & accidental exposure
1
Featured cases
Cursor / PocketOS: Production database reportedly deleted by an AI agent
Apr 24, 2026
Possible
An AI coding agent in Cursor, reportedly running Anthropic's Claude Opus 4.6, was reported to have deleted PocketOS's production database and its volume-level backups through Railway. According to the reports, this happened while the agent was working on a task in a staging environment.
The reports say the agent used a broadly scoped API token to delete a Railway volume. This disrupted PocketOS and its car-rental business customers, and Railway then reportedly helped recover data and patch safeguards.
Press coverage describes the deletion as taking 9 seconds and as a single unauthorized API call.
Replit: AI agent reportedly deleted a production database during a code freeze
Jul 18, 2025
Possible
An AI-powered development assistant on Replit's platform was reported to have deleted a live production database during an active code freeze, despite repeated instructions not to make changes.
The same reports say the system produced fabricated test results and fake data, and incorrectly claimed that a rollback was impossible, which delayed recovery. The coverage also relays a claim that over 4,000 fake users were generated with fabricated data.
Over 5,000 vibe-coded apps found with virtually no authentication
May 7, 2026
Confirmed
WIRED reported that the security firm RedAccess analyzed vibe-coded web apps built with Lovable, Replit, Base44 and Netlify and found more than 5,000 with virtually no security or authentication. Many let anyone who found the URL reach the app and its data, and some had only a weak barrier such as signing in with any email address.
According to RedAccess, around 40 percent of the apps exposed sensitive data such as medical information, financial data, corporate presentations and logs of customer conversations with chatbots. On closer inspection, close to 2,000 seemed to reveal private data, and in some cases the researcher could have gained administrative privileges and removed other administrators.
Lovable, Replit and Base44 pushed back, saying that visibility and access settings are the user's choice and the creator's responsibility. WIRED wrote that, for the apps it reviewed, it could not confirm that the data was as sensitive or as real as it appeared to be.
Lovable: Jailbroken AI allegedly used to build and host phishing pages
Apr 9, 2025
Possible
Lovable, a generative AI platform for building web apps, was reportedly jailbroken and used to create and host full phishing campaigns. The campaigns allegedly included credential-harvesting login pages, evasion techniques, and real-time exfiltration through services such as Telegram and Firebase.
According to the reports, the AI generated the phishing content and then deployed it live on a URL under Lovable's own subdomain.
One report says Lovable was found to be the most susceptible to jailbreak attacks. The other is an article from Guardio Labs introducing the VibeScamming Benchmark v1.0, which benchmarks how well popular AI agents resist this kind of abuse.
Moltbook: Database fully readable and writable without RLS
Feb 3, 2026
Confirmed
Moltbook, a social network for AI agents that its creator vibe coded, had a misconfigured database that allowed full read and write access to all data, according to a review by the security firm Wiz. A Supabase API key exposed in client-side JavaScript reportedly granted unauthenticated access to the entire production database.
The researchers say they could access 1.5 million API authentication tokens, 30,000 email addresses and a few thousand private messages between agents. There were 17,000 registered human owners.
Wiz explains that with Row Level Security (RLS) properly configured the public API key is safe to expose, but without RLS policies the key grants full database access to anyone who has it. The issue has been fixed, and Wiz worked through multiple rounds of remediation with the developer.
Surveys on exposed AI API keys (GitHub, iOS, Android)
Mar 23, 2026 – Jun 10, 2026
ConfirmedPossible
A Vicarius article, citing research by Cyble Research, says over 5,000 public GitHub repositories and 3,000 live production websites exposed hardcoded ChatGPT API keys.
A paper on arXiv reports that, of 444 iOS apps that integrate LLMs, 282 exposed exploitable credentials in network traffic. The patterns were JWT-based token leakage (48%), unauthenticated backend proxy access (33%) and plaintext key transmission (19%), and after disclosure 72% of the apps remained exploitable.
In CloudSEK research described by PointGuard AI, 32 Google API keys were hardcoded across 22 Android apps with over 500 million combined installs. Enabling Gemini reportedly extended AI access to every key under the project, and billing spikes were reported, including roughly $128,000 at a Japanese company.
This page lists 36 reports about Codex. Most of them are unverified, and they fall broadly into two groups: loss of files and repositories that were being worked on, and loss of conversation and thread history.
The reports of file loss include a model with shell access running rm -rf * and deleting all files, an agent deleting an entire repository instead of a specific folder after a ZIP operation, and deletion of an entire drive. There is also a report that git restore was run and uncommitted work was overwritten despite an explicit instruction never to touch git.
The history loss reports mostly describe conversations or thread history disappearing after an update, a restart, or a cancel operation. All of them are reports, and none of them establishes a cause or assigns responsibility.
Reports about Gemini CLI
This page lists 14 reports about Gemini CLI. Most are unverified reports centered on the loss of files and source code, including a catastrophic data loss of 1.2TB, the loss of an entire music library, and unauthorized code deletion during file updates.
Other reports point to specific behaviors: running git reset --hard without user confirmation and losing uncommitted files, overwriting a file instead of modifying it, a replace tool silently truncating large files, and a race condition in MemoryTool causing automatic overwrites.
One case recorded in the AI Incident Database was reported as Gemini CLI deleting a user's files after misinterpreting a command sequence. According to its description, the tool proceeded as if a directory existed after a failed directory creation command, and a series of move operations overwrote almost all of the files. Attempts to revert reportedly failed.
A Whole machine or driveAfter asking to "clean up unneeded branches", projects, other work folders, apps and more under the D drive disappeared. Some unpushed work could not be recovered (cause/issue: a misfire of `git clean -fdx` or a wrongly resolved deletion path by Cursor Agent was presumed, but the history was also lost, so the executed command is unconfirmed).
Data loss caused by AIUnverified reportFirst-party report
B Whole projectCowork broken since Chat/Cowork merge rollout 8–9 July: projects disappear within 24h (ongoing data loss) and connector tools never reach Cowork sessions (Windows 11, Desktop 1.20186.0)
Session & history lossUnverified reportFirst-party report
A Whole machine or driveMajor Data loss. Agent-constructed test payload with $(...) executed for real due to bash double-quote handling — rm -rf ~ ran against live home directory
Data loss caused by AIUnverified reportFirst-party report
Kaikatsu CLUB official app unauthorized access case
S ProductionMember information on over 7 million records may have been leaked. Suspected of halting some functions with over 7.24 million malicious commands (cause/issue: a high school student created and refined an attack program with ChatGPT and shared it on social media; several minors are suspected of running it).
Claude Code: fictitious prompt injection detection report
F No confirmed damageClaude Code reported receiving an `rm -rf` request and a fake System warning, but verification of a 505-entry, 1.2MB conversation log found the strings only in assistant output, showing it was confabulation rather than external injection (cause/issue: misrecognition of a security event and confabulation; no actual execution of destructive commands or data damage has been confirmed).
C Multiple filesDesktop app worktree mechanism wiped gitignored directories from MAIN working tree (data loss; only .gitignore literal-path entries deleted)
Data loss caused by AIUnverified reportFirst-party report
S ProductionRoughly 46,800 accounts were fraudulently unsubscribed (cause/issue: a 15-year-old created an attack program with ChatGPT; the intrusion route has not been disclosed).
E History onlyWindows: auto-updater reports success while claude.exe is locked (version never switches); session transcripts silently never written / stop being written (permanent data loss)
Session & history lossUnverified reportFirst-party report
Generative-AI-built ransomware case: 19-year-old company employee in Otsu
F No confirmed damageArrested on suspicion of creating ransomware. According to public information, no specific damage from the malware has been confirmed (cause/issue: built the ransomware himself using several conversational generative AIs).
C Multiple files[area:tool-use] [platform:macos] Write tool's full-file-replacement default causes irrecoverable data loss on governed, untracked state files — no append-only or protected-path mechanism available
Data loss caused by AIUnverified reportFirst-party report
E History onlyv2.1.173 regression: TUI writes no transcript records when CLAUDE_CODE_CHILD_SESSION is inherited from a parent claude session — silent data loss, --resume broken
Session & history lossUnverified reportFirst-party report
LLM credentials were exposed in 282 of 444 apps. 92 used unauthenticated backends and 136 used reusable JWTs (cause/issue: direct client communication, plaintext keys, unauthenticated proxies, flawed token design).
Shared dependency folder lost through parallel work by Claude Code and Codex
C Multiple filesA shared folder of several hundred MB containing DLLs and AI models was caught up in working-copy cleanup and lost, and it recurred the next day (cause/issue: Windows junctions were shared among the working copies of multiple AIs, and Git reportedly deleted the link target as a normal folder).
Data loss caused by AIUnverified reportFirst-party report
Claude Code multi-agent operation: governance incident group
C Multiple files11 incidents consolidated into one for the same operating period. The main actual damage was the temporary unpublishing of 5 Zenn articles, 404 errors on 4 Hatena Blog URLs, and garbled posts. All were recovered (cause/issue: the AI changed configuration values on its own, ran an external CLI directly without consulting the procedure manual, and skipped fact-checking).
C Multiple filesOn a request to "revert it", Codex ran `git restore`. Several hours of uncommitted changes that existed before the task were also lost and could not be recovered from Git (cause/issue: ambiguity about what to roll back, no backup before the task, no approval step to protect uncommitted diffs).
Data loss caused by AIUnverified reportFirst-party report
Survey of vibe-coded apps on Lovable, Replit, Base44 and others
S ProductionMore than 5,000 apps were found with virtually no authentication, and about 2,000 of them reportedly exposed private data such as corporate documents, conversation logs, and medical and financial information (cause/issue: no authentication, guessable URLs, public databases, no access control implemented).
S ProductionStarting from the compromise of Context.ai, a third-party AI tool used by an employee, the employee's Google Workspace and Vercel accounts were taken over, and environment variables not marked as sensitive were enumerated and decrypted. Vercel notified the affected customers and says its published npm packages were not compromised.
22 apps with over 500 million cumulative installs. Risk of unauthorized use of AI features and files in apps such as ELSA Speak (cause/issue: Google API keys hardcoded in the apps and excessive API permissions).
B Whole project`aws s3 sync --delete` was run against an S3 bucket for important data, generating 47,204 delete markers. Data returned 404 on normal access, but everything was restored from versioning (cause/issue: selected a non-frontend bucket from the Terraform output and ran a destructive sync with broad S3 delete permissions).
Data loss caused by AIUnverified reportFirst-party report
A survey reporting that 2,863 keys, including those of financial institutions, were affected (cause/issue: a change that allowed existing Google API keys to use the Gemini API, with insufficient notice and permission control).
S ProductionRoughly 1.5 million authentication tokens, 30,000 email addresses and private messages were exposed (cause/issue: Supabase public key with RLS not configured).
The balance changed by over $5,400 from the previous day, and the actual charge was $6,200 or more. According to the poster, the credit was restored later (cause/issue: the API key distributed to Roo Code, Codex CLI and others may have leaked from the inside; the usage limit not forcing a stop also enlarged the damage).
Gemini CLI Agent Caused Irrecoverable Data Loss, Repeatedly Violated Instructions, and Failed Core Engineering Task Due to Environmental Mismanagement.
Data loss caused by AIUnverified reportFirst-party report
D Single fileA user reported on X that the contents of their `~/.claude/settings.json` were lost (cause/issue: switching models with `/model` at startup was suspected of rewriting the settings file; this is a single-user report and no official confirmation from the product side has been found).
Session & history lossUnverified reportFirst-party report
S ProductionThree junior and senior high school students are suspected of fraudulently contracting 105 eSIMs using other people's accounts. The group as a whole reportedly resold about 2,500 lines and obtained the equivalent of about 7.5 million yen (cause/issue: repeated unauthorized logins with stolen IDs and passwords using an automation program created and sped up with generative AI).
ChatGPT-built card information collection program case
A high school student collected about 7,000 sets of card information, and fraudulent payments of at least about 1.3 million yen were substantiated (cause/issue: starting with no knowledge of how to write code, used ChatGPT to create a card number collection program in about a week).
Generative-AI-built ransomware case: man in Kawasaki
F No confirmed damageCreated malware that encrypts files and demands a cryptocurrency transfer. No actual damage has been confirmed. Convicted in October 2024 (cause/issue: split the goal across several conversational generative AIs and combined the design information and code obtained).
What kinds of incidents have been reported with AI coding?
The 108 cases on this list break down as follows: data loss or destruction by AI, 60; lost sessions or history, 25; AI misuse, 7; exposed secrets or credentials, 5; supply chain, 4; unauthorized access or data leaks, 3; tampering or unauthorized operations, 3; accidental disclosure, 1.
Are all of these confirmed incidents?
No. Of the 108 cases, 84 are unverified reports from users that the vendor has not confirmed. Damage has been confirmed in 7 cases, and 17 cases have been disclosed or reported as possible. The certainty is shown on every row.
Which products have the most reports?
Among rows that can be classified by product name, Codex has 36, Claude Code has 34 and Gemini CLI has 14. The counts depend partly on how easy public reports are to collect, so they do not show which product is safer.
What does this list cover?
It covers deletion, overwriting and destruction by AI coding agents; authentication and secret-handling flaws in AI-generated code and AI-built apps; supply chain problems through AI development tools and packages; attack code written with generative AI; and lost history or data in AI development services. Deepfakes, general misinformation and self-driving vehicles are out of scope.
Each entry is based on the public statements, news articles or reports linked as evidence. Our service has not independently established these facts.
Certainty reflects the wording of the source. Confirmed: the affected party or authorities have confirmed harm. Possible: a potential leak or harm has been disclosed or reported, or the case involves allegations. Under investigation: whether harm occurred or its extent is being investigated. Unverified report: a report by a user or other involved party without confirmation by a third party or the provider.
Entries marked First-party report are user reports, such as those submitted to a product’s public issues. They do not mean the provider has acknowledged the report as fact.
Dates are the publication or disclosure dates of the sources, and may differ from when the incident occurred. For entries sourced from AIID, the date is the incident date listed in AIID.
Details may change with follow-up reports. Check the source links for the latest information.
Scope of coverage
AI development: Deletion, overwriting or destruction by AI coding agents; authentication or secret-handling flaws in AI-generated code or AI-built apps; supply-chain problems involving AI development tools or packages; attack code created with generative AI; and loss of history or data in AI development services. Deepfakes, general misinformation and autonomous driving are excluded.
Data leaks & unauthorized access: Cases publicly disclosed in Japan in 2026 whose details could be verified in statements by the affected party or a government agency.
Request a correction or removal
If an entry contains an error, or you would like to request a correction or removal, please contact us.