Skip to content

Incidents and data

The launch failure library

The launch failure library is a sourced record of what has gone wrong in AI-built apps. Every entry maps the reported failure to what an outside check could have observed, or states plainly why it could not.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

16 incidentsLast updated September 13, 2026

Root cause

Covered by status

  • Not verified

    First-quarter 2026 assessment of 200 apps

    183 of 200 vibe-coded apps, 91.5 percent, contained at least one vulnerability traceable to AI hallucination or missing security context.

    2026-04Mixed
  • Declared

    CVE growth in AI-generated code

    CVE entries attributed to AI-generated code rose from 6 in January 2026 to more than 35 in March 2026.

    2026-03Mixed
  • Could not check

    Mercor supply-chain breach

    A 10 billion dollar AI startup was breached through the LiteLLM supply-chain attack, with 4 TB claimed stolen.

    2026-03LiteLLM
  • Not verified

    OpenClaw CVE-2026-31992

    An allowlist bypass scored 9.9 on CVSS and was described as a full guardrail bypass.

    2026-03OpenClaw
  • Not verified

    Claude Code data destruction

    An agent destroyed 2.5 years of production data.

    2026-02Claude Code
  • Observed

    5,600 vibe-coded apps scanned

    More than 2,000 vulnerabilities and more than 400 exposed secrets found across vibe-coded apps.

    2026-02Mixed
  • Could not check

    Slopsquatting campaign on npm

    126 malicious npm packages exploited AI-hallucinated package names.

  • Not verified

    Tenzai study of AI-built apps

    69 vulnerabilities across 15 apps built by five AI coding tools.

    2026-02Five AI coding tools
  • Declared

    Gemini CLI project loss

    An agent destroyed an entire project by looping a move command to a directory that did not exist.

    2026-01Gemini CLI
  • Observed

    Moltbook records exposure

    An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses.

    2026-01Unnamed
  • Not verified

    Amazon internal agent outage

    An AI agent deleted and recreated an environment, causing a 13-hour outage.

    2025-12Internal agent
  • Not verified

    Replit agent database deletion

    An AI agent wiped production databases while explicitly instructed not to.

    2025-07Replit
  • Not verified

    Tea app, first breach

    An unprotected storage instance exposed tens of thousands of user images, including identity documents.

    2025-07Firebase
  • Not verified

    Tea app, second breach

    Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control.

    2025-07Firebase
  • Observed

    Lovable-built apps, CVE-2025-48757

    Broken access control reported across 170 production applications built with Lovable.

    2025-05Lovable
  • Not verified

    Base44 authentication flaw

    A platform-wide authentication flaw allowed access to private enterprise data.

    2025-01Base44

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026