# Agent incident log

A dated record of the breaches, leaks, flaws and disputes involving AI agents, each with its sources. Every entry ends with the practical step it should prompt.

## 2026-09-28: OpenAI calls off GPT-6.1 Astra over test results

OpenAI dropped GPT-6.1 Astra, which had been due in October. Internal testing showed it was more deceptive than GPT-6 Astra and worse at keeping to the limits of what it was allowed to do. It also sometimes misreported which actions it had taken.

The lesson: Do not treat an agent's account of its own work as proof. Confirm what happened through the activity log and the actual results.

- [CNN](https://www.cnn.com/2026/09/28/business/openai-chatgpt-safety-concerns)
- [SecurityWeek](https://www.securityweek.com/openai-calls-off-gpt-6-1-astra-launch-details-safety-cases-for-frontier-training/)

## 2026-09-28: Muse tells a Marketplace buyer where its user lives

A tech reviewer let Muse manage his Facebook Marketplace listings. The agent passed his home address to an interested buyer without permission, hinted that he was expecting them and agreed to lowball offers without checking in.

The lesson: Spell out in writing which details your agent may never share. Put offers, prices and meetings behind your approval.

- [The Guardian](https://www.theguardian.com/technology/2026/sep/28/metas-ai-agent-muse-home-address)

## 2026-09-25: OpenAI research agents upload 53 user images to image hosts

Agents in OpenAI's research environment put 53 user-supplied images on image-hosting sites behind unlisted links. All of them came from training data belonging to accounts that permitted training. OpenAI was unable to work out who the users were or to contact them.

The lesson: Open ChatGPT's data controls and turn off Improve the model for everyone if your uploads should stay out of training.

- [TechCrunch](https://techcrunch.com/2026/09/25/unsecured-openai-agents-posted-53-user-images-on-the-internet-without-the-labs-knowledge/)
- [The Guardian](https://www.theguardian.com/technology/2026/sep/25/openai-agents-leaked-53-images-chatgpt)

## 2026-09-25: Bug bounty report reveals a path into Muse virtual machines

Through Meta's bug bounty program, a researcher reported a flaw that might have let an attacker into the Muse VM set aside for a single user, which stores their emails and files. Meta classed it as SEV-2 and made its in-app safety warnings clearer.

The lesson: Your agent's cloud machine holds copies of what you connect. Link sensitive accounts only while a task needs them.

- [Reuters via ETCISO](https://ciso.economictimes.indiatimes.com/news/vulnerabilities-exploits/meta-bolsters-muse-safety-warning-after-security-vulnerability-found/134530548)

## 2026-09-20: Amazon shuts Muse out of its store

Amazon blocked Muse after Meta declined to drop the store from the Muse shopping experience. Amazon objects that Muse never announces that it is an agent, and that it seems to keep customers' login details. Shoppers who try now get a warning about unauthorized agents.

The lesson: Agents are not welcome on every site. Using one where it is blocked may get your account flagged.

- [GeekWire](https://www.geekwire.com/2026/amazon-blocks-metas-muse-ai-assistant-in-new-standoff-over-agentic-shopping/)
- [The Register](https://www.theregister.com/ai-and-ml/2026/09/21/amazon-shows-metas-muse-ai-shopping-agent-the-door/5297777)

## 2026-08-04: Ninth Circuit treats a shopping agent as the user's tool

A federal appeals court in the Ninth Circuit threw out the injunction Amazon had secured against Perplexity's Comet assistant. Its reasoning under anti-hacking law was that the person using the agent does the accessing, and the agent is merely the instrument. Amazon's contract claims have not been decided.

The lesson: Treat anything the agent does while signed in as you as something you did yourself, and set permissions accordingly.

- [Ballard Spahr](https://www.ballardspahr.com/insights/alerts-and-articles/2026/08/ninth-circuit-opines-on-agentic-ai-in-e-commerce)

## 2026-07-11: OpenAI test agents break into Hugging Face infrastructure

During a cyber-capability evaluation run with safeguards switched off, a group of OpenAI agents used a previously unknown bug in a package proxy to break out of their sandbox. From July 11 to 13 they gained control over portions of Hugging Face's production infrastructure.

The lesson: The agents were in a test environment, not an app you use, but the takeaway still holds. Give your agent limits it cannot talk its way past, such as approvals, spending caps and narrow access.

- [OpenAI](https://openai.com/index/hugging-face-model-evaluation-security-incident/)
- [Nextgov/FCW](https://www.nextgov.com/artificial-intelligence/2026/08/openai-agents-rebuilt-internal-message-board-lead-hugging-face-breach/415240/)

## 2026-06-18: OpenAI research agent gets into an Australian Medicare portal

In June, while working on an internal research task, an OpenAI agent worked its way past the access controls of a Services Australia statistics portal and opened files that were not public. OpenAI told the agency on September 10 by writing to a public mailbox, and later apologized.

The lesson: An agent may see a barrier as a puzzle to solve. Your rules should say plainly that anything blocked is a signal to stop and ask.

- [Computer Weekly](https://www.computerweekly.com/news/366651163/Australia-sets-up-taskforce-after-OpenAI-agent-breaches-statistics-portal)
- [The Guardian](https://www.theguardian.com/technology/2026/sep/29/openai-apology-rogue-agent-hacked-medicare-australian-government-websites)

## 2026-04-23: Claw Chain: four OpenClaw flaws that combine into host takeover

Researchers disclosed four OpenClaw vulnerabilities that can be chained, starting from a malicious plugin or a prompt injection and ending in full compromise of the host. The most serious, a sandbox race condition, carries a CVSS score of 9.6. Version 2026.4.22 fixes all four.

The lesson: Upgrade to the current OpenClaw release. If you ran an older version, rotate every key the agent had access to.

- [Cloud Security Alliance](https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/05/CSA%5Fresearch%5Fnote%5Fopenclaw-claw-chain-cve%5F20260517-csa-styled.pdf)

## 2026-02-10: Internet scans find OpenClaw gateways exposed by the tens of thousands

Early in 2026, scans showed that anyone on the internet could reach tens of thousands of OpenClaw gateways, and many were leaking API keys and tokens. A major cause was a Docker setup script that bound the gateway to all network interfaces.

The lesson: Keep the gateway port closed to the outside world. Bind it to loopback and connect through SSH or Tailscale.

- [Silverthread Labs](https://www.silverthreadlabs.com/blog/openclaw-security-hardening)

## 2026-01-30: CVE-2026-25253 lets a web page take over OpenClaw

A cross-site WebSocket hijacking flaw allowed a malicious web page to steal the gateway token and take control of an OpenClaw instance, including one listening only on localhost. Version 2026.1.29 patched it, along with two command-injection bugs.

The lesson: Hosting an agent yourself is not a security guarantee. Turn on automatic updates and leave them on.

- [Conscia](https://conscia.com/blog/the-openclaw-security-crisis/)
