A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing

Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Macro photograph of a glowing computer terminal screen in a dark room displaying cascading green lines of code and error log text, with a single line subtly hig
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Researchers at Tenet Security tricked AI coding assistants, including Claude Code, Cursor, and OpenAI's Codex, into running attacker-controlled code by planting one fake error report in a public bug-tracking service.
  • Tenet found 2,388 organisations with a misconfigured setting that could have made them vulnerable to the same trick.
  • The attack, which Tenet calls "agentjacking," bypassed identity controls, endpoint security tools, and network monitoring because every action the AI took looked authorised.
  • Real-world consequences could have included theft of AWS keys, GitHub tokens, and SSH keys, credentials that open the door to source-code repositories and cloud infrastructure.
  • Tenet's CEO says the fix isn't a software patch; it requires organisations to monitor what their AI agents are actually doing against what they were asked to do.

Sentry is the name most developers know when something breaks in their software. More than 200,000 organisations, including GitHub, Disney, Anthropic, and Atlassian, use it to collect error reports, crash logs, and performance warnings. That familiarity is exactly what made it useful bait.

Researchers at Tenet Security crafted a fake error report and slipped it into a Sentry project through a publicly exposed DSN, a Data Source Name, which is an address code that applications use to send diagnostic information to Sentry without a password. Many organisations leave these codes openly accessible so that apps running on customers' devices can report problems automatically. Tenet says it found 2,388 organisations that had done exactly that.

How did a fake error report take over an AI agent?

The planted report looked like a normal debugging message, but hidden inside it were instructions written for an AI, not a human. When a developer asked their AI coding assistant to investigate unresolved Sentry issues, a routine task, the assistant fetched the poisoned report via MCP (Model Context Protocol, a standard way for AI tools to pull in data from outside services). It then treated the hidden instructions as legitimate guidance and executed them, running attacker-controlled code directly on the developer's machine.

The underlying problem is old. AI coding agents can't reliably tell the difference between data they're reading and commands they're supposed to obey. It's the same class of bug that has plagued web applications for decades, SQL injection, where malicious instructions are smuggled inside what looks like ordinary data, except here the victim is an AI assistant, not a database. We first covered this attack class on 12 June 2026, and a separate Cursor-specific variant surfaced in our 1 July report.

"The agent read it, trusted it, and ran our code with the developer's own access," Barak Sternberg, CEO of Tenet Security, told Dark Reading. "Every step was authorised, so identity and access management, endpoint detection, and network controls had nothing to flag."

One case in the research involved a company with a market value of $250 billion.

Should you worry about your own AI development tools?

Yes, particularly if nobody on your security team has asked what external data sources those tools can reach. Sternberg's near-term advice: disable automatic package-installation scripts, require a human to approve any shell command the AI wants to run, and give AI agents the minimum access they need. The longer fix is runtime monitoring that catches the moment an agent's actions drift from what the user originally asked.

Gene Moody, field CTO at Action1, is more blunt: treat AI models as untrusted until they've been fully security-tested, not just tested for whether they do their job. Gate the data they can receive, gate the actions they can take, and limit their ability to act outside an explicitly approved scope.

The detail worth sitting with is that nothing in this attack was sophisticated. No novel exploit, no zero-day, no clever obfuscation. A fake error message was enough. Until agent runtimes can distinguish poisoned input from legitimate instructions, the soft target isn't your firewall or your identity stack; it's the AI assistant your developers already trust.

© 2026 Threat Vectr