https://shipreadyai.dev/incidents

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# Launch failure library

Every page under https://shipreadyai.dev/incidents, 17 in total.

- [Launch failure library](https://shipreadyai.dev/incidents.md): 16 documented incidents in apps built with AI tools, each with its sources.
- [First-quarter 2026 assessment of 200 apps](https://shipreadyai.dev/incidents/first-quarter-2026-assessment.md): 2026-04. 183 of 200 vibe-coded apps, 91.5 percent, contained at least one vulnerability traceable to AI hallucination or missing security context.
- [CVE growth in AI-generated code](https://shipreadyai.dev/incidents/cve-growth-2026.md): 2026-03. CVE entries attributed to AI-generated code rose from 6 in January 2026 to more than 35 in March 2026.
- [Mercor supply-chain breach](https://shipreadyai.dev/incidents/mercor-supply-chain-breach.md): 2026-03. A 10 billion dollar AI startup was breached through the LiteLLM supply-chain attack, with 4 TB claimed stolen.
- [OpenClaw CVE-2026-31992](https://shipreadyai.dev/incidents/openclaw-cve-2026-31992.md): 2026-03. An allowlist bypass scored 9.9 on CVSS and was described as a full guardrail bypass.
- [Claude Code data destruction](https://shipreadyai.dev/incidents/claude-code-data-destruction.md): 2026-02. An agent destroyed 2.5 years of production data.
- [5,600 vibe-coded apps scanned](https://shipreadyai.dev/incidents/five-thousand-six-hundred-apps-scanned.md): 2026-02. More than 2,000 vulnerabilities and more than 400 exposed secrets found across vibe-coded apps.
- [Slopsquatting campaign on npm](https://shipreadyai.dev/incidents/slopsquatting-npm-campaign.md): 2026-02. 126 malicious npm packages exploited AI-hallucinated package names.
- [Tenzai study of AI-built apps](https://shipreadyai.dev/incidents/tenzai-study.md): 2026-02. 69 vulnerabilities across 15 apps built by five AI coding tools.
- [Gemini CLI project loss](https://shipreadyai.dev/incidents/gemini-cli-project-loss.md): 2026-01. An agent destroyed an entire project by looping a move command to a directory that did not exist.
- [Moltbook records exposure](https://shipreadyai.dev/incidents/moltbook-records-exposure.md): 2026-01. An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses.
- [Amazon internal agent outage](https://shipreadyai.dev/incidents/amazon-internal-agent-outage.md): 2025-12. An AI agent deleted and recreated an environment, causing a 13-hour outage.
- [Replit agent database deletion](https://shipreadyai.dev/incidents/replit-agent-database-deletion.md): 2025-07. An AI agent wiped production databases while explicitly instructed not to.
- [Tea app, first breach](https://shipreadyai.dev/incidents/tea-app-first-breach.md): 2025-07. An unprotected storage instance exposed tens of thousands of user images, including identity documents.
- [Tea app, second breach](https://shipreadyai.dev/incidents/tea-app-second-breach.md): 2025-07. Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control.
- [Lovable-built apps, CVE-2025-48757](https://shipreadyai.dev/incidents/lovable-cve-2025-48757.md): 2025-05. Broken access control reported across 170 production applications built with Lovable.
- [Base44 authentication flaw](https://shipreadyai.dev/incidents/base44-auth-flaw.md): 2025-01. A platform-wide authentication flaw allowed access to private enterprise data.
