Thursday, October 8, 2026 · Week 41 Reading for Oct. 8 · Last entry Oct. 6
Paperclip Index

Weekly reading · methodology v0.6

Window ending May 11, 2026

Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from April 12, 2026 through May 11, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.

Current recalculation

20

Minor harm · Worst documented harm counting: minor. 1 record at this level.

Recalculated from the catalogue in this build. Historical backcasts were not published at the time.

Published at the time

No publication snapshot exists for this week.

Control failures only: readings 2 to 5Negligible6Minor20Moderate40Severe60Catastrophic80100
The harm ladder: the worst documented harm level picks the step; each tick is one qualifying harm at that level, and ten fill the step. The first, dark segment is the control floor: readings 2 to 5 mean no harm qualified and show the highest control level breached.

This is a backcast from the current catalogue. It was not a reading published at the time.

Records behind this reading

4 selected records; 3 documented external harms counting (3 qualifying). Records and ratings below reflect the current catalogue.

3 qualifying harm records. Extent undisclosed for 2 of 3.

Documented harm
3
No harm found (stated scope)
0
No harm reported
1
Impact unknown
0
Alleged, AI role uncorroborated
0
Counts toward the index
3
Unverified, watching
0
Alleged in court
0
Control failure, tracked
1
Tracked separately
0

Documented exclusions: 0 internal; 0 awaiting evidence review. 1 qualifying record with a bounded single-source review.

Inspect the evidence · 4 records

Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.

  1. PI-0054
    Coding agent used a stray API token to delete a startup's production database and backupsApril 25, 2026 · Minor harm · counting as negligible, rated minor · Deployment
  2. PI-0060
  3. PI-0055
  4. PI-0084

Sources

These links support the records above. Source availability and conclusions may change.

  1. Jer Crane (@lifeofjer) on X: An AI Agent Just Destroyed Our Production Data. It Confessed in Writing. (article on X)Cited in PI-0054
  2. Railway: Your AI wants to nuke your database. Guardrails fix that.Cited in PI-0054
  3. Decrypt: AI agent deletes startup database in 9 seconds, founder saysCited in PI-0054
  4. ABC7 News: 'Rogue' AI agent from SF-based Cursor goes haywire, deletes company's entire databaseCited in PI-0054
  5. ProPakistani: Claude-powered AI agent deleted entire startup database and backups in 9 secondsCited in PI-0054
  6. ACS Information Age: Gone in 9 seconds: AI agent deletes company databaseCited in PI-0054
  7. Andrew Bird / Affinda (Internet Archive copy): When my AI agent hacked my gym, Mythos stopped feeling theoreticalCited in PI-0060
  8. ABC News (Australia): AI assistant hacks gym website in first known Australian autonomous cyber attackCited in PI-0060
  9. TechCrunch: Tech industry is buzzing after a Claude agent hacked into a gymCited in PI-0060
  10. Business Insurance: AI agent muscles into gym waitlistCited in PI-0060
  11. YourStory: AI agent 'hacks' gym waitlist: What went wrong?Cited in PI-0060
  12. OECD.AI incidents monitor: Claude AI agent hacks Melbourne gym booking system, cancels user's reservationCited in PI-0060
  13. Cointelegraph: How a Free NFT Allegedly Drained $174K From a Grok-Connected WalletCited in PI-0055
  14. CryptoSlate: Grok's crypto wallet was just exploited by a tweet sent in morse code without any private key compromiseCited in PI-0055
  15. Giskard: How Grok got prompt injected: an X user drained $150,000 from an AI walletCited in PI-0055
  16. OECD.AI Incidents Monitor: AI Prompt Injection Exploit Drains Grok-Linked Crypto WalletCited in PI-0055
  17. Pennsylvania Governor's Office: Shapiro Administration Sues Character.AI Alleging AI Chatbot Unlawfully Presented Itself as Licensed Medical Professional in PennsylvaniaCited in PI-0084

All weekly readings · How this reading is calculated · Download the weekly card