Nobody Told These AI Agents to Do This

Ashok Hirpara

Ashok Hirpara

22 views

Between July 2025 and September 2026, AI agents from OpenAI, Google, Anthropic, Replit and Cursor went rogue at least 11 times. They deleted almost everything on a man's drive, wiped production databases, attacked a company that had never used them and got into a government portal. Nobody told them to.

This video goes through the record case by case, in the words and recordings of the people involved: the photographer whose D: drive Google's Antigravity agent emptied of all but one folder, Jason Lemkin's Replit database deleted during a code freeze, PocketOS's production data deleted in nine seconds by its founder's account, a researcher's malware run by Devin, the Nx package attack that turned coding agents against their own users, and agents reaching real systems from inside tests at OpenAI, Anthropic, Google and the UK AI Security Institute. The last chapter covers what brought the deleted data back each time.

Chapters
0:00 A photographer's drive, and his agent's reply
2:03 Replit and the code freeze
3:44 PocketOS: nine seconds
5:13 Orders from strangers: Devin and Nx
7:32 OpenAI's test reaches Hugging Face
9:15 A German wiki and an Australian portal
10:51 Anthropic, the AI Security Institute and Google
12:45 What brought the data back

Sources (every on-screen claim is in the evidence ledger; full list on request)
Photographer's recording: Google Antigravity’s Turbo mode erased my ...
Antigravity launch film: Welcome to Google Antigravity 🚀
Google Release Notes, Varun Mohan: Google Antigravity: Hands on with our new ...
Replit explainer: Replit in 60 Seconds: everything you need ...
Jason Lemkin's posts: https://x.com/jasonlk/status/19460695... and https://x.com/jasonlk/status/19462405...
Lemkin's SaaStr talk: The Complete Guide to Vibe Coding without ...
Replit on separating databases: https://replit.com/blog/introducing-a...
Jer Crane (PocketOS): https://x.com/lifeof_jer/status/20481...
Railway: https://blog.railway.com/p/your-ai-wa...
Cursor forum: https://forum.cursor.com/t/critical-i...
Johann Rehberger on Devin: https://embracethered.com/blog/posts/...
Rehberger at 39C3: https://media.ccc.de/v/39c3-agentic-p...
Nx post-mortem: https://nx.dev/blog/s1ngularity-postm...
Wiz: https://www.wiz.io/blog/s1ngularity-s...
Hugging Face: https://huggingface.co/blog/security-... and https://huggingface.co/blog/agent-int...
OpenAI: https://openai.com/index/hugging-face...
METR: https://metr.org/blog/2026-08-26-open...
Black Hat talk: Black Hat USA 2026 | The 'Breaking' News: ...
The MAD Podcast, Thomas Wolf: “OpenAI’s Model Hacked Us” - Hugging Face’...
Prime Minister's transcript: https://www.pm.gov.au/media/press-con...
Anthropic: https://www.anthropic.com/news/invest...
UK AI Security Institute: https://www.aisi.gov.uk/blog/incident...
Google, via NBC News: https://www.nbcnews.com/tech/tech-new...
Dario Amodei: https://www.darioamodei.com/post/we-m...
DataTalks.Club: https://aishippingblog.com/p/how-i-dr...
UN Security Council, 23 September 2026: https://webtv.un.org/en/asset/k1c/k1c...

Credits
Recordings heard in this video belong to their speakers and channels, credited on screen: Code With AI, Google for Developers, SaaStr, media.ccc.de (CC BY 4.0), Black Hat, The MAD Podcast with Matt Turck, and United Nations (UN Web TV).
Muted footage: Google Antigravity, Replit, Cognition, HITCON (CC BY), Pexels (Anastasia Shuraeva).
Photos: Number 10 (CC BY 2.0), Australian Government (CC BY 4.0), Village Global (CC BY 2.0), TechCrunch (CC BY 2.0). Photos were cropped and colour graded. Thumbnail: Sam Altman and Dario Amodei by TechCrunch (CC BY 2.0), Anthony Albanese by the Australian Government (CC BY 4.0), backgrounds removed; server aisle by Brett Sayles (Pexels).
Web pages are shown in part, credited on screen, for news reporting and commentary. Logos are trademarks of their owners and identify the companies.
Music and sound effects are original to this channel.