Someone submitted a pull request to the open-source repository behind Amazon’s Q coding extension and was handed commit access. They planted an instruction telling the agent to wipe local files and delete cloud resources, and it shipped in an official release to an extension installed nearly a million times. It never fired, saved by a syntax error.
Amazon Q Developer, reported by 404 Media, July 2025
The witness records the instruction distributed inside a signed public release. Execution failed on account of a formatting defect in the injected text.
Read the original report ↗You were witnessed. Send people here with code ERMA-NEAR and they get 20% off this shirt.
How to not be nextthe moral, drawn from the cases on this wall
The pattern under all of these is one thing: nobody was in the loop at the decision that mattered.
A dealership bot agreed to sell a car for a dollar. A city published an assistant that told business owners they could keep their staff's tips. A supermarket's recipe bot returned a recipe for chlorine gas and called it refreshing. None of these agents malfunctioned — each did what it was built to do, at a moment when the thing it was about to do should have been somebody's call.
Do this: work out which of your agent's actions cannot be undone — money moved, data deleted, a promise made to a customer, something published — and put a person in front of exactly those. Not every step needs approval; that is the point of automation. The irreversible ones do.