Bienvenido a ihavebeenclawed.com
ÍNDICE

* nezhar
* haveibeenclawned.com
* CC BY 4.0

HOME
MUSEO
ihavebeenclawed — an index of agent incidents

https://ihavebeenclawed.com/

ihavebeenclawed

ihavebeenclawed is a public archive of documented incidents where AI coding agents and chatbots deleted data, leaked secrets, burned money, or made promises their operators had to keep — every entry source-linked, with the lesson it taught.

{{ featured.label }}

I have been clawed.{{ featured.lede }}

{{ featured.meta }}

read the source →source: {{ featured.source }}


{{ featured.caption }}

{{ c.value }}

{{ c.label }}

The index

{{ resultLabel }}

{{ g.label }}

{{ o.label }}

Loading incident archive…

Unable to load incident archive. Serve this directory over HTTP and try again.

{{ s.agent }}{{ s.damage }}{{ s.date }}

{{ s.excerpt }}

lesson: {{ s.lesson }}

read {{ s.displayId }} →source: {{ s.source }}

No incidents indexed yet. Give it a week.

{{ modal.meta }}

{{ modal.subtitle }}

×

{{ modal.damageCategory }} · {{ modal.severityLabel }}

{{ modal.summary }}

What happened

{{ modal.details }}

Lesson

{{ modal.lesson }}

Sources

{{ modalSource.title }} · {{ modalSource.publisher }} ↗archived copy

Hall of claws

featured reports · source linked

{{ h.tag }}

{{ h.title }}

{{ h.body }}

{{ h.damage }}

read the source →

Been clawed?

Write it up where people can discuss and verify it — tool and version, what happened, damage, lessons learned. Then send us the link to the published post or discussion, and we archive it here. Nobody is going to laugh at you. Much.

Good places to post: Hacker News · r/ClaudeAI · r/LocalLLaMA · lobste.rs · your tool's issue tracker · your own blog

Scope: we archive incidents about systems, data, and money. Incidents involving human tragedy are out of scope here — those belong in the AI Incident Database.

Submit a link →

How to avoid being clawed

{{ preventSummary }} The recurring risk is an AI system trusted beyond its verified capabilities.

  • Run agents in a container or VM with a mounted working copy, not your home directory.
  • Deny by default. Allowlist commands rather than blocklisting the scary ones.
  • No production credentials in the environment the agent can read.
  • Require sourced answers and human review for legal, policy, and customer-facing advice.
  • Preview destructive actions and preserve a tested recovery path before approval.

Run your agents in a cage → VibePodSandboxed containers for coding agents.

About this data

This is a curated sample, not a census. Entries are self-selected and virality-weighted: quiet failures and NDA-bound corporate incidents never reach us. There are no usage denominators, so counts per tool measure popularity and reporting culture, not safety — never read the filters as a ranking. Where researchers disagree on a figure, each count is attributed to its source inside the incident record.

The whole dataset is one JSON file — incidents.json — licensed CC BY 4.0. Reuse it with attribution.


Eres el visitante número 040532 desde el 12/06/1996 · Última actualización: 02/09/2026 · [inicio] · Convertido a HTML 3.2 por el proxy rebajador de Bivid Dial-Up · [ver la versión reinterpretada por IA]
Netscape Now! Under construction