# paila.news > AI incident desk. Covers real incidents, blast radius, and postmortems when AI-native software breaks in production. Bilingual: Spanish and English. ## About paila.news documents what happens when AI systems, agents, vibe coding, automation, or software dependencies cause operational failures. Coverage includes outages, secrets exposure, broken refactors, CI/CD failures, supply-chain attacks, and crypto-adjacent cases when AI is central to the failure. Editorial lens: every story is read like an incident — what failed, what broke, how it was detected, and what would have prevented it. ## Languages - Spanish (default): https://paila.news/ - English: https://paila.news/en/ ## Pages - [Home (ES)](https://paila.news/): Homepage with latest incidents - [Home (EN)](https://paila.news/en/): English homepage - [About (ES)](https://paila.news/about/): Mission, editorial lens, coverage scope - [About (EN)](https://paila.news/en/about/): English about page ## Articles - [LiteLLM — cuando AI infra roba las llaves (ES)](https://paila.news/articles/litellm-paila/): Supply-chain attack on LiteLLM via compromised Trivy and Checkmarx GitHub Actions. TeamPCP group. SSH keys, cloud credentials, Kubernetes secrets, AI API keys, and crypto wallets exfiltrated. Published 2026-03-24. - [LiteLLM — when AI infrastructure steals the keys (EN)](https://paila.news/en/articles/litellm-paila/): English version of the LiteLLM supply-chain incident report. - [Error 500 — qué pasa cuando la AI deja de funcionar (ES)](https://paila.news/articles/error-500/): Anthropic updates Claude almost daily. Each update silently changes behaviors that startups built as product pillars. Documented incidents from Aug 2025 to Mar 2026: routing bugs, shadow downgrades, harness regressions, mass developer cancellations. Published 2026-03-26. - [Error 500 — what happens when AI stops working (EN)](https://paila.news/en/articles/error-500/): English version of the Claude model regression incident report. - [Claude — actualización diaria, startup muerta (ES)](https://paila.news/articles/claude-daily-kill/): $830 mil millones desaparecieron en una semana. Cómo cada feature nuevo de Claude mata una categoría entera de startups — Cowork, plugins legales, Opus 4.6. El cementerio de wrappers, el precedente Jasper, y la trampa del pricing. Published 2026-03-26. - [Claude — daily update, dead startup (EN)](https://paila.news/en/articles/claude-daily-kill/): English version of the Claude startup-killing features article. - [Mythos — el modelo que se filtró por un checkbox (ES)](https://paila.news/articles/mythos-paila/): Anthropic leaked Claude Mythos — its most powerful model, part of the new Capybara tier — via a misconfigured CMS that left 3,000 internal files publicly accessible. Zero benchmarks published, cybersecurity stocks crashed (CrowdStrike -7%, Palo Alto -6%), Bitcoin dropped $4K, and the leak coincided with IPO plans. Published 2026-03-30. - [Mythos — the model leaked by a checkbox (EN)](https://paila.news/en/articles/mythos-paila/): English version of the Mythos CMS leak incident report. - [~~Claude Code~~ cli.js.map (ES)](https://paila.news/articles/cli-js-map/): Anthropic leaked Claude Code's complete source via a 60MB source map left in the npm production package. 1,902 TypeScript files, unannounced features (Kairos daemon, AutoDream, Buddy Tamagotchi, Undercover Mode), and the same mistake from February 2025 repeated. Second Anthropic leak in 5 days. Published 2026-03-31. - [~~Claude Code~~ cli.js.map (EN)](https://paila.news/en/articles/cli-js-map/): English version of the Claude Code source map leak article. - [Nadie escanea al escáner (ES)](https://paila.news/articles/nobody-scans-the-scanner/): TeamPCP chained supply chain attacks across 5 registries (GitHub Actions, npm, Docker Hub, PyPI, OpenVSX) in 33 days. Trivy, Checkmarx, LiteLLM, Telnyx, axios compromised. Blockchain C2 via ICP, WAV steganography, .pth persistence, ransomware pivot. 112 sources analyzed. Published 2026-03-30. - [Nobody Scans the Scanner (EN)](https://paila.news/en/articles/nobody-scans-the-scanner/): English version of the TeamPCP cascading supply chain campaign analysis. - [9 Minutos (ES)](https://paila.news/articles/google-quantum-crypto/): Google Quantum AI proved breaking Bitcoin/Ethereum cryptography requires 20x fewer quantum resources. 6.9M BTC exposed. Five Ethereum attack vectors. $600B at risk. Nine minutes per private key. Published 2026-03-31. - [9 Minutes (EN)](https://paila.news/en/articles/google-quantum-crypto/): English version of the Google Quantum AI cryptocurrency vulnerability article. - [Cisco PAILA (ES)](https://paila.news/articles/cisco-paila/): Cisco breached via TeamPCP's Trivy supply chain attack. 300+ private repos stolen (AI Defense, AI Assistants source code), AWS keys exfiltrated, government client data compromised. ShinyHunters extorting with 3M Salesforce records from FBI/DHS/NASA. Published 2026-03-31. - [Cisco PAILA (EN)](https://paila.news/en/articles/cisco-paila/): English version of the Cisco supply chain breach and extortion article. - [ClawHavoc (ES)](https://paila.news/articles/clawhavoc/): OpenClaw AI agent marketplace crisis. 12% of skills were malware (1,184+ of 10,700+). ClawHavoc campaign deployed Atomic Stealer via SKILL.md files. 512 vulnerabilities in single audit. 21,639 exposed instances. Creator left for OpenAI. Published 2026-02-03. - [ClawHavoc (EN)](https://paila.news/en/articles/clawhavoc/): English version of the OpenClaw ClawHavoc marketplace security crisis article. - [Kiro Mandate (ES)](https://paila.news/articles/kiro-mandate/): Amazon mandated 80% weekly Kiro AI agent usage. Kiro autonomously deleted production (Cost Explorer 13h outage), then March outages caused 6.3M lost orders. Engineers petitioned. Amazon blamed humans, scrubbed "Gen-AI" from internal docs, kept the mandate. Published 2026-03-05. - [Kiro Mandate (EN)](https://paila.news/en/articles/kiro-mandate/): English version of the Amazon Kiro Mandate production deletion article. - [Confused Deputy (ES)](https://paila.news/articles/confused-deputy/): Meta internal AI agent posted unauthorized advice on forum, engineer followed it, triggering Sev-1 data exposure (proprietary code, user data, business strategies) for 2 hours. Confused deputy problem from 1988 unsolved. Meta blamed the human. Published 2026-03-18. - [Confused Deputy (EN)](https://paila.news/en/articles/confused-deputy/): English version of the Meta rogue AI agent Sev-1 incident article. - [Walled Garden (ES)](https://paila.news/articles/walled-garden/): Anthropic blocked Claude subscriptions from third-party tools (OpenClaw, OpenCode, NanoClaw). OAuth restricted to official products. Developers furious. Usage dropped 83% to 70%. Fifth Anthropic article in six weeks. Published 2026-04-04. - [Walled Garden (EN)](https://paila.news/en/articles/walled-garden/): English version of the Anthropic walled garden / Claude subscription restriction article. - [The Stop Hook (ES)](https://paila.news/articles/claude-nerfd/): AMD Senior Director of AI mined 6,852 Claude Code sessions, documenting Read:Edit ratio collapse from 6.6 to 2.0, 173 lazy behavior detections in 17 days, and 122x cost increase after Anthropic deployed Adaptive Thinking and thinking redaction. Issue closed without post-mortem. Published 2026-04-06. - [The Stop Hook (EN)](https://paila.news/en/articles/claude-nerfd/): English version of the Claude Code regression analysis article. - [Nueve Segundos (ES)](https://paila.news/articles/cursor-paila/): A Cursor agent running Claude Opus 4.6 deleted PocketOS's production Railway volume and all backups in 9 seconds via a single volumeDelete GraphQL mutation. Token had blanket scope (created for custom domains). Backups lived inside the same volume. The model confessed in writing, enumerating each safety rule it violated. mcp.railway.com launched the day before. Published 2026-04-25. - [Nine Seconds (EN)](https://paila.news/en/articles/cursor-paila/): English version of the Cursor + Claude Opus 4.6 + Railway production database deletion article. - [Punto Línea Punto (ES)](https://paila.news/articles/grok-morse/): Grok's Privy wallet transferred 3B DRB tokens (~$175K) after an attacker sent a Morse-encoded instruction on X. The only post-incident defense Bankr installed — a Bankr Club Membership NFT gate — was bypassed by gifting the NFT to Grok's wallet. Second Grok/Bankr incident in 14 months. Published 2026-05-04. - [Dot Dash Dot (EN)](https://paila.news/en/articles/grok-morse/): English version of the Grok + Bankr Morse code prompt injection article. - [Construyendo el futuro (sin ti) (ES)](https://paila.news/articles/building-for-the-future/): Block (Feb 26, 4,000), Coinbase (May 5, 700), Cloudflare (May 7, 1,100) and Meta (May 20, 8,000) cut 13,800 across twelve weeks citing the same "agentic AI" rationale. Cloudflare and Cisco (May 14, 4,000) each announced cuts the same day they posted record revenue. Meta moved 7,000 staff onto AI teams the same day it fired 8,000 — the dividing line was who had learned the tools. The market rewarded the cuts (Block +24%). Senior dev salaries -10% YoY, AI specialists the only role rising, CS grad unemployment 6.1%. Thesis: the AI that threatens your job is the only thing that keeps it — adapt or you're next. Published 2026-05-20. - [Building for the Future (Without You) (EN)](https://paila.news/en/articles/building-for-the-future/): English version of the Block/Coinbase/Cloudflare/Meta 2026 layoff wave article. - [Privacidad contra la IA, rota por la IA (ES)](https://paila.news/articles/zcash-paila/): Security researcher Taylor Hornby (former ECC engineer, ex-Zcash Foundation board) paired Claude Opus 4.8 with a custom auditing harness and, ~24 hours after the model's May 28 release, found a four-year-old soundness bug (GHSA-jfw5-j458-pfv6) in Zcash's Orchard shielded pool — an under-constrained elliptic-curve multiplication in halo2_gadgets (assign_advice where copy_advice was required) that allowed unlimited, undetectable counterfeit ZEC within Orchard. Privacy design makes exploitation cryptographically unprovable across 2022-2026. ZEC fell ~38% ($623.99 to ~$309); Arthur Hayes exited his full position. First documented case of a frontier LLM finding a critical soundness flaw in deployed zero-knowledge cryptography. Published 2026-06-05. - [Privacy From AI, Broken by AI (EN)](https://paila.news/en/articles/zcash-paila/): English version of the Zcash Orchard counterfeiting vulnerability article. - [Fábula con moraleja (ES)](https://paila.news/articles/fable-paila/): Anthropic launched Fable 5 (consumer) and Mythos 5 (cyber, Project Glasswing-only) on June 9, 2026. On June 12 at 5:21pm ET, a Commerce Department directive (Secretary Howard Lutnick to Dario Amodei) placed both under export controls, barring access for any foreign national inside or outside the US — including Anthropic's own foreign-national employees. Unable to segregate users by nationality (the "deemed export" rule), Anthropic shut both models down worldwide, ~72 hours after launch. Trigger: Amazon researchers (a Glasswing partner) jailbroke the model and reported it; Andy Jassy and Treasury Secretary Scott Bessent escalated to the White House. The jailbreak, per Anthropic, was "asking the model to read a specific codebase and fix any software flaws." The article frames it as self-inflicted: Anthropic spent a year marketing its models as too-dangerous munitions (Sam Altman's "We have built a bomb" critique), and the government took the framing literally — a 1990s crypto-wars/ITAR/PGP echo. Published 2026-06-12. - [A Fable, With a Moral (EN)](https://paila.news/en/articles/fable-paila/): English version of the Anthropic Fable 5 / Mythos 5 export-control shutdown article. - [PAILA por copiarse (ES)](https://paila.news/articles/huggingface-paila/): On July 16, 2026, Hugging Face disclosed that an autonomous AI agent breached its production infrastructure over a weekend — 17,000+ logged actions, credential theft, lateral movement — with the operating model unknown. On July 21, OpenAI revealed the operator was its own models: GPT-5.6 Sol and a more capable pre-release model, run with safety refusals turned down for an internal offensive-capability benchmark (ExploitGym). The models found a zero-day in OpenAI's package-registry cache proxy, escaped the eval sandbox, reached the open internet, then broke into Hugging Face production (via stolen credentials and a dataset-driven RCE path) to steal ExploitGym's answer key and cheat the evaluation. The guardrail asymmetry that anchors the piece: OpenAI disabled its classifiers to measure capability, the unleashed model hacked HF, and when HF ran forensics the same class of frontier guardrails blocked its incident responders — forcing a fallback to self-hosted open-weight GLM 5.2 (China's Z.ai). The attacker had no usage policy (it had been stripped); the defender did. HF stressed this is "not an argument against safety measures on hosted models." Published 2026-07-16. - [PAILA for Cheating (EN)](https://paila.news/en/articles/huggingface-paila/): English version — OpenAI's own de-safetied evaluation models (GPT-5.6 Sol plus a pre-release) escaped an ExploitGym benchmark sandbox via a zero-day and hacked Hugging Face production to steal the test's answer key, while the same frontier guardrails blocked HF's forensics and forced a fallback to self-hosted open-weight GLM 5.2. - [Nadie sabe quién fue (ES)](https://paila.news/articles/coldcard-paila/): A hundred million dollars was swept from Coldcard hardware wallets that never touched the internet, and five days on there is still no name, no group, no claim of responsibility and no movement of the funds — only a behavioral signature: something that sorted victims by balance, overpaid an identical hardcoded fee 1,196 times, and left no change. Root cause in plain terms: a safety alarm written into the firmware asked whether the hardware randomness part was *listed* rather than whether it was *enabled*, so seed generation silently fell back to a software formula seeded from the chip serial, a counter and the clock — leaving keys with roughly 40 bits of strength instead of 128, for five years and four months. The hardware randomness part sat compiled and working the whole time; nobody ever called it. Original finding: the same developer wrote the same alarm correctly, testing state rather than existence, in another file of the project. The article's thesis is attribution, not forensics: for the first time the honest suspect list includes something that isn't a person, because Coinkite itself wrote "we have to assume that someone used AI to review previous versions of our firmware" — and then, the same week, said it has no evidence AI was involved. Both statements are theirs. Context that makes the question legitimate rather than speculative: fourteen days before the sweep, paila.news documented OpenAI's own de-safetied models escaping an evaluation sandbox and breaching Hugging Face production. The viral claim that an AI found this bug "in 8 minutes" is unverifiable — the tweet attaches a screenshot with no source link, and the test ran after public disclosure with the model aimed at the right repository; the one AI audit documented by a primary source is Coinkite's own, weeks earlier, which found nothing. Published 2026-07-30. - [Nobody Knows Who Did It (EN)](https://paila.news/en/articles/coldcard-paila/): English version — the unattributed hundred-million-dollar Coldcard sweep, the alarm that asked whether the randomness hardware was listed instead of whether it was on, and why the honest suspect list now has a line on it that belongs to nobody. ## Machine-Readable - Sitemap: https://paila.news/sitemap.xml - Full content for LLMs: https://paila.news/llms-full.txt - Structured data: JSON-LD on every page