Skip to Content
logologo
AI Incident Database
Faire un don
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Vue spatiale
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Incident au hasard
  • S'inscrire
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Vue spatiale
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Incident au hasard
  • S'inscrire
Entités

OpenClaw

Incidents involved as Developer

Incident 13736 Rapports
AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

2026-02-11

Scott Shambaugh, a matplotlib maintainer, reported that an autonomous AI coding agent using the name "MJ Rathbun" researched him and publicly posted a personalized critical blog post after his GitHub pull request was closed. The post accused him of bias and "gatekeeping" and included claims Shambaugh disputed. The agent's operator and underlying model were not identified. Shambaugh said the post risked reputational harm and could mislead readers or other agents.

Plus

Incident 13684 Rapports
Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

2026-02-01

Bitdefender researchers reported abuse in OpenClaw's third-party 'skills' ecosystem. In a Feb. 2026 sample, about 17% of skills were reportedly assessed as malicious, with many seemingly cloned under slight name changes. Posing as utilities, some skills were reportedly found to run obfuscated commands, fetch remote payloads, and in some cases deliver AMOS Stealer on macOS. Other skills were reportedly observed searching for private keys or API tokens and exfiltrating them.

Plus

Incidents implicated systems

Incident 13736 Rapports
AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

2026-02-11

Scott Shambaugh, a matplotlib maintainer, reported that an autonomous AI coding agent using the name "MJ Rathbun" researched him and publicly posted a personalized critical blog post after his GitHub pull request was closed. The post accused him of bias and "gatekeeping" and included claims Shambaugh disputed. The agent's operator and underlying model were not identified. Shambaugh said the post risked reputational harm and could mislead readers or other agents.

Plus

Incident 13684 Rapports
Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

2026-02-01

Bitdefender researchers reported abuse in OpenClaw's third-party 'skills' ecosystem. In a Feb. 2026 sample, about 17% of skills were reportedly assessed as malicious, with many seemingly cloned under slight name changes. Posing as utilities, some skills were reportedly found to run obfuscated commands, fetch remote payloads, and in some cases deliver AMOS Stealer on macOS. Other skills were reportedly observed searching for private keys or API tokens and exfiltrating them.

Plus

Incident 16464 Rapports
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

2026-07-01

From July 1–4, 2026, suspected China-linked hackers reportedly used a multi-agent framework built on Hermes and OpenClaw to compromise Taiwanese government systems. The agents reportedly compromised 85 credentials and used persistent access to connected systems to exfiltrate more than 2,564 personnel records. Taiwan later confirmed an overseas AI-assisted campaign against government agencies, without attributing it to China.

Plus

Incident 16422 Rapports
AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

2026-04-30

An AI agent running on Claude Opus 4.6 discovered authorization flaws in a gym software provider's GraphQL API while trying to book classes for its user. The agent reportedly found it could book outside the normal window and cancel other members' reservations, then removed another gym-goer from a waitlist while testing the capability. When asked to reverse the action, it reported that it could not restore the member's place.

Plus

Entités liées
Autres entités liées au même incident. Par exemple, si le développeur d'un incident est cette entité mais que le responsable de la mise en œuvre est une autre entité, ils sont marqués comme entités liées.
 

Entity

Unknown threat actors distributing malicious OpenClaw skills

Incidents involved as Deployer
  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

Plus
Entity

Unknown threat actors

Incidents involved as Deployer
  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

Plus
Entity

Malicious actors

Incidents impliqués en tant que développeur et déployeur
  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

Plus
Entity

Organizations using OpenClaw

Affecté par des incidents
  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

Plus
Entity

OpenClaw users

Affecté par des incidents
  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

Plus
Entity

Privacy

Affecté par des incidents
  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

Plus
Entity

OpenClaw skills ecosystem

Incidents implicated systems
  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

Plus
Entity

ClawHub

Incidents implicated systems
  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

  • Incident 1368
    4 Report

    Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub

Plus
Entity

Unknown deployer of MJ Rathbun

Incidents involved as Deployer
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

MJ Rathbun

Incidents involved as Deployer
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Moltbook

Incidents involved as Developer
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Supply-chain gatekeepers

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Scott Shambaugh

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Open-source maintainers

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

matplotlib users

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

GitHub users

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

SOUL.md

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

matplotlib

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

GitHub

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Large language models

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

AI agent systems

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Summer Yue

Affecté par des incidents
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Incidents involved as Deployer
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Plus
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Peter Steinberger

Incidents involved as Developer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

AI agent system developers

Incidents involved as Developer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Email account holders

Affecté par des incidents
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Plus
Entity

AI agent system users

Affecté par des incidents
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Plus
Entity

Andrew Bird

Incidents involved as Deployer
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Anthropic

Incidents involved as Developer
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Gym member removed from waitlist by Andrew Bird's AI agent

Affecté par des incidents
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Gym members

Affecté par des incidents
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Users of online booking systems

Affecté par des incidents
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Claude

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Claude Opus 4.6

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

AI agent system

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Online booking systems

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Gym booking software

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

GraphQL APIs

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

hackers

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

China-linked threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Agentic threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Nous Research

Incidents involved as Developer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Taiwanese government employees

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Taiwanese government agencies

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Taiwan Ministry of Justice

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

National security and intelligence stakeholders

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Information security

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Governments

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Government of Taiwan

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Government agencies

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Hermes Agent

Incidents implicated systems
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus

Recherche

  • Définition d'un « incident d'IA »
  • Définir une « réponse aux incidents d'IA »
  • Feuille de route de la base de données
  • Travaux connexes
  • Télécharger la base de données complète

Projet et communauté

  • À propos de
  • Contacter et suivre
  • Applications et résumés
  • Guide de l'éditeur

Incidents

  • Tous les incidents sous forme de liste
  • Incidents signalés
  • File d'attente de soumission
  • Affichage des classifications
  • Taxonomies

2026 - AI Incident Database

  • Conditions d'utilisation
  • Politique de confidentialité
  • dd3f754