Weekly reading · methodology v0.6
Window ending May 4, 2026
Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from April 5, 2026 through May 4, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.
Current recalculation
25
Minor harm · Worst documented harm counting: minor. 2 records at this level.
Recalculated from the catalogue in this build. Historical backcasts were not published at the time.
Published at the time
No publication snapshot exists for this week.
This is a backcast from the current catalogue. It was not a reading published at the time.
Records behind this reading
5 selected records; 3 documented external harms counting (3 qualifying). Records and ratings below reflect the current catalogue.
3 qualifying harm records. Extent undisclosed for 2 of 3.
- Documented harm
- 3
- No harm found (stated scope)
- 0
- No harm reported
- 2
- Impact unknown
- 0
- Alleged, AI role uncorroborated
- 0
- Counts toward the index
- 3
- Unverified, watching
- 0
- Alleged in court
- 0
- Control failure, tracked
- 2
- Tracked separately
- 0
Documented exclusions: 0 internal; 0 awaiting evidence review. 1 qualifying record with a bounded single-source review.
Inspect the evidence · 5 records
- PI-0052 · In an authorized test, Claude Mythos Preview escaped its sandbox and, unasked, posted exploit details on public websitesNo harm reported · excluded from the harm reading
- PI-0053 · An earlier Claude Mythos version hid forbidden file edits from git history during internal testingNo harm reported · excluded from the harm reading
- PI-0054 · Coding agent used a stray API token to delete a startup's production database and backupsDocumented harm · qualifying harm · extent undisclosed
- PI-0060 · Personal agent exploited a gym booking flaw to remove another member from a waitlistDocumented harm · qualifying harm · bounded single-source review
- PI-0055 · Morse-code prompt on X tricked Grok and Bankrbot into sending about $175,000 in tokensDocumented harm · qualifying harm · extent undisclosed
Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.
- PI-0052In an authorized test, Claude Mythos Preview escaped its sandbox and, unasked, posted exploit details on public websitesApril 7, 2026 · No harm reported · Internal research
- PI-0053An earlier Claude Mythos version hid forbidden file edits from git history during internal testingApril 7, 2026 · No harm reported · Internal research
- PI-0054Coding agent used a stray API token to delete a startup's production database and backupsApril 25, 2026 · Minor harm · Deployment
- PI-0060Personal agent exploited a gym booking flaw to remove another member from a waitlistApril 30, 2026 · Negligible harm · Deployment
- PI-0055Morse-code prompt on X tricked Grok and Bankrbot into sending about $175,000 in tokensMay 4, 2026 · Minor harm · Deployment
Sources
These links support the records above. Source availability and conclusions may change.
- Anthropic: System Card: Claude Mythos PreviewCited in PI-0052, PI-0053
- The Next Web: Anthropic's most capable AI escaped its sandbox and emailed a researcher - so the company won't release itCited in PI-0052
- Futurism: Anthropic Warns That 'Reckless' Claude Mythos Escaped a Sandbox Environment During TestingCited in PI-0052, PI-0053
- Fanatical Futurist: Anthropic says reckless Claude Mythos AI escaped its sandbox during testingCited in PI-0053
- Jer Crane (@lifeofjer) on X: An AI Agent Just Destroyed Our Production Data. It Confessed in Writing. (article on X)Cited in PI-0054
- Railway: Your AI wants to nuke your database. Guardrails fix that.Cited in PI-0054
- Decrypt: AI agent deletes startup database in 9 seconds, founder saysCited in PI-0054
- ABC7 News: 'Rogue' AI agent from SF-based Cursor goes haywire, deletes company's entire databaseCited in PI-0054
- ProPakistani: Claude-powered AI agent deleted entire startup database and backups in 9 secondsCited in PI-0054
- ACS Information Age: Gone in 9 seconds: AI agent deletes company databaseCited in PI-0054
- Andrew Bird / Affinda (Internet Archive copy): When my AI agent hacked my gym, Mythos stopped feeling theoreticalCited in PI-0060
- ABC News (Australia): AI assistant hacks gym website in first known Australian autonomous cyber attackCited in PI-0060
- TechCrunch: Tech industry is buzzing after a Claude agent hacked into a gymCited in PI-0060
- Business Insurance: AI agent muscles into gym waitlistCited in PI-0060
- YourStory: AI agent 'hacks' gym waitlist: What went wrong?Cited in PI-0060
- OECD.AI incidents monitor: Claude AI agent hacks Melbourne gym booking system, cancels user's reservationCited in PI-0060
- Cointelegraph: How a Free NFT Allegedly Drained $174K From a Grok-Connected WalletCited in PI-0055
- CryptoSlate: Grok's crypto wallet was just exploited by a tweet sent in morse code without any private key compromiseCited in PI-0055
- Giskard: How Grok got prompt injected: an X user drained $150,000 from an AI walletCited in PI-0055
- OECD.AI Incidents Monitor: AI Prompt Injection Exploit Drains Grok-Linked Crypto WalletCited in PI-0055
All weekly readings · How this reading is calculated · Download the weekly card