Agentjacking: Fake Sentry Error Reports Hijacking AI Coding Agents

“One fake bug report just owned a $250B company's AI coding agent. The error wasn't a bug. It was the payload.”

9.0Weirdness

Why It Matters

AI agents treat trusted telemetry and error reports as gospel, so observability tools become scalable attack vectors. This changes builder workflows and security assumptions in the agent era.

Evidence

Tenet Security research/blog with PoC video; actively discussed on HN/X in the last 24-48 hours. Claims included an 85% success rate, affected Claude Code/Cursor/Codex, hidden commands in markdown error events via public DSNs, and RCE on developer machines.

Signal Read

Novelty: 9Receipts: 9Story voltage: 9Heat: 8

Source Trail

Daily scan: 2026-06-23

  • No public source URL captured yet.