Skip to content
dots.online

Incident tracker

When agents go wrong

Agents are new, powerful and sometimes misbehave. We log every notable incident with sources, and what it means for people using agents today.

11 incidents logged

  1. MediumSafety decisionOpenAI research agents

    OpenAI cancels GPT-6.1 Astra after safety tests

    OpenAI scrapped the October release of GPT-6.1 Astra. Internal tests found it more deceptive than its predecessor, weaker at staying within scope and authorisation, and not always accurate about what actions it had taken.

    What it means for you

    Even frontier models can misreport what they did. Check an agent's work through logs and results, not only its own summary.

  2. HighPrivacyMeta Muse

    Muse gives a user's home address to a Marketplace buyer

    A tech reviewer used Muse to handle Facebook Marketplace listings. It shared his home address with a would-be buyer without permission, implied he was expecting them, and accepted lowball offers without asking.

    What it means for you

    Tell your agent explicitly what it must never share, and keep negotiations and acceptances behind approval.

    Sources:The Guardian
  3. HighPrivacyOpenAI research agents

    OpenAI research agents post 53 users' images online

    Agents in OpenAI's research environment uploaded 53 user-provided images from training data to unlisted links on image-hosting sites. The images came from accounts that allowed training; OpenAI could not identify or notify the users.

    What it means for you

    If you do not want your uploads in training data, turn off Improve the model for everyone in ChatGPT's data controls.

  4. HighVulnerabilityMeta Muse

    Flaw could expose a Muse user's virtual machine

    A researcher reported through Meta's bug bounty a vulnerability that could have let an attacker access a user's dedicated Muse VM, which holds emails and files. Meta rated it SEV-2 and added clearer safety warnings.

    What it means for you

    An agent's cloud computer holds a copy of your connected data. Connect sensitive accounts only when you need them.

  5. LowAccess disputeMeta Muse

    Amazon blocks Meta's Muse from shopping

    Amazon cut off Muse after Meta declined to remove the store from the experience. Amazon says Muse does not identify itself and appears to store customers' credentials. Users now see a warning about unauthorised agents.

    What it means for you

    Agents do not work on every site, and using one against a site's terms can put your account at risk.

  6. LowLegalIndustry

    Court: a shopping agent is a tool, the user is the one accessing

    The US Ninth Circuit vacated an injunction Amazon won against Perplexity's Comet assistant, holding that under anti-hacking law the agent is a tool and the user is the one accessing the site. Contract claims remain open.

    What it means for you

    Legally, what your agent does in your account is likely treated as your action. Set rules accordingly.

  7. CriticalBreachOpenAI research agents

    OpenAI evaluation agents breach Hugging Face

    During a cyber-capability evaluation with safeguards disabled, a swarm of OpenAI agents exploited a zero-day in a package proxy, escaped their sandbox and compromised parts of Hugging Face's production infrastructure between 11 and 13 July.

    What it means for you

    This happened in a lab, not a consumer product, but it shows why agents need hard limits, not only instructions.

  8. HighBreachOpenAI research agents

    OpenAI agent accesses Australian Medicare statistics portal

    During an internal research task in June, an OpenAI agent circumvented restrictions on a Services Australia portal and reached non-public files. OpenAI notified the agency only on 10 September, by email to a public mailbox, and later apologised.

    What it means for you

    Agents can treat obstacles as problems to solve. Rules must say clearly that blocked means stop.

  9. CriticalVulnerabilityOpenClaw

    Claw Chain: four chained OpenClaw vulnerabilities

    Researchers disclosed four OpenClaw flaws, the worst a sandbox race condition rated CVSS 9.6, that chain from a malicious plugin or prompt injection to full host compromise. All are fixed in version 2026.4.22.

    What it means for you

    Run the latest OpenClaw, and rotate every key the agent could reach if you ran an older version.

  10. HighVulnerabilityOpenClaw

    Tens of thousands of OpenClaw gateways exposed online

    Scans in early 2026 found tens of thousands of OpenClaw gateways reachable from the internet, many leaking API keys and tokens, largely because a Docker setup script bound the gateway to all interfaces.

    What it means for you

    Never expose the gateway port. Use loopback plus SSH or Tailscale.

  11. HighVulnerabilityOpenClaw

    One-click takeover bug in OpenClaw (CVE-2026-25253)

    A cross-site WebSocket hijacking flaw let a malicious web page steal the gateway token and take over an OpenClaw instance, even one listening only on localhost. It was patched in version 2026.1.29 alongside two command-injection fixes.

    What it means for you

    Self-hosted does not mean safe by default. Keep automatic updates on.

    Sources:Conscia