Redditor Icy_Student_5770 claims a Claude Code transcription subagent's incidental ps check surfaced an xmrig miner that had been silently mining Monero on 6 of his 8 Mac cores for 15 days, leading to a full backdoor, a stolen password, and a tie to a ~15,500-Mac botnet โ corroboration of the infection and its botnet attribution would establish agent workflows as credible incidental intrusion detectors on developer machines, while debunking or silence closes it as a one-off anecdote.
state: acceleratingheat: highuncertainty: mediumconvergesscott: mediumagentic-security incident-detectionIcy_Student_5770
Surfaced 2026-10-07T11:35:53Z โ My Claude Code agents kept stalling. One of them noticed a crypto miner that had been on my Mac for 15 days โ The Thompson incident's circulation is now itself the story: front-page Reddit at 97th-percentile velocity where commenters scrutinize mechanism (how Claude saw /etc/zshenv changes, port 5900 exposure) rather than debunk or replicate, plus an HN filing that hasn't caught. That cross-platform spread โ magnitude-valve reading, two platforms, hot agentic-security band โ moves the case to accelerating on the episode's reach, but the movement is amplification of one named account, not new independent instances, so heat prices medium (high only if the HN thread catches) and this look earns no material change.
What is this?
Reddit user Icy_Student_5770 reports that a Claude Code transcription subagent, while debugging agent stalls, ran an incidental `ps` check that surfaced an xmrig miner silently mining Monero on 6 of his 8 Mac cores for 15 days โ an investigation he says then uncovered a full backdoor, a stolen password, and a tie to a ~15,500-Mac botnet. A second, named instance surfaced days later: Stratechery's Ben Thompson wrote that Claude Code's persistent monitor tool flagged a real compromise on his Mac Mini, with commenters questioning the mechanism but not debunking it. The supplied web results do not cover either incident directly โ nothing here independently verifies the Reddit post's specifics, the botnet attribution, or Thompson's account beyond the Stratechery article itself. What the snippets do establish is background plausibility: XMRig/Monero cryptojacking is a well-documented, resurging threat class that includes macOS as a target (Fortinet lists XMRig as cross-platform including macOS; G DATA documented a 2025 resurgence; The Record covered a pirated-Final-Cut-Pro miner campaign on Apple computers).
Why it matters to Scott
Ben Thompson โ a consequential, named party โ now publicly documents Claude Code's persistent monitor tool catching a real compromise on his Mac Mini, the second independent instance of the exact inversion Scott's canon already holds (agents as incidental security sensors, carried by the Breach Doesnt Compose ebook and his agent-observability work), turning one anonymous Reddit `ps` anecdote into a replicated, dated, citable pattern for his observability writing and LeverageAI security-advisory angle. The receipts stay soft โ Thompson's mechanism is questioned by commenters and the Stratechery primary source is not yet directly grounded, while the Reddit specifics (15-day xmrig, stolen password, ~15,500-Mac botnet tie) remain unverified โ so this strengthens a held claim rather than settling it: a dated-receipts opportunity worth surfacing, but medium, not high, until Thompson's account is grounded first-hand.
ip:source.breach-doesnt-compose-ebookip:concept.agent-observabilityip:source.observability-for-agentic-systems-what-to-log-how-to-redact-how-to-debug-ebookdev:technology.claude-coderadar:concept.agentic-securityradar:concept.agent-securityradar:concept.agent-observabilityradar:concept.claude-code
queries asked of Scott's wikis
- agents as incidental security sensors
- Breach Doesnt Compose agent detection claims
- Claude Code subagent monitor tool harness patterns
- subagent stall debugging transcript workflows
- agent tool sandboxing host command blast radius
- agent observability host environment drift detection
Measured heat
now 0 pts/hpeak 116 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 200h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion
How the heat travelled
pace: p92 vs 1188 stories at the 168h mark (now 200h old) โ ahead of nvidia-open-agent-safety-platform (1.0x), behind reflection-open-weight-release (1.0x)
Evidence (3) โ โญ canonical anchor
Interpretation history
2026-10-07T11:33:56Z
magnitude valve eligible (multi-platform, top-decile engagement) and never alerted; deterministic escalation to deliver
2026-10-07T11:24:17Z
evidence attached: hn.story.49991163 โ Second high-profile instance of Claude flagging a developer machine as compromised (Ben Thompson's Mac Mini) โ independent corroboration or a false-positive debunk directly re-judges the incidental-detector hypothesis.
2026-10-07T04:34:18Z
grounded: converges/medium โ Ben Thompson โ a consequential, named party โ now publicly documents Claude Code's persistent monitor tool catching a real compromise on his Mac Mini, the secon
2026-10-07T04:25:37Z
Ben Thompson's Stratechery account of Claude Code's persistent monitor tool flagging a real compromise on his Mac Mini gives the pattern a second, independent, named first-party instance โ different person, machine, and mechanism from the anonymous Reddit post โ so the case now stands on a replicated agent-as-incidental-detector pattern rather than a single anecdote. The original post's specifics (15-day xmrig, backdoor, ~15,500-Mac botnet tie) remain uncorroborated, so the promotion rests on pattern replication, not on that account's verification.
2026-10-07T03:33:13Z
evidence attached: reddit.post.1wzkpu9 โ Independent corroboration: Ben Thompson's Claude Code monitor tool flagged a real crypto-miner compromise on his Mac, a second first-party incident supporting agent workflows as incidental intrusion detectors.
2026-10-03T08:35:02Z
grounded: known/low โ Scott's own canon already carries the exact claim this incident instantiates โ the Breach Doesnt Compose ebook matches 'agents as incidental security sensors โ
2026-10-03T08:25:48Z
case created โ A concrete, checkable first-person incident where an agent workflow surfaced live malware, and no open case covers the agent-as-accidental-intrusion-detector angle, so it earns a seed slot despite being a single low-engagement post.
Decision trace
- 10-11 16:44review_screenjev screen: no material development (noul=0.19)
- 10-08 03:28sensor_dirtycomment_update
- 10-08 00:59attention_routeThe editor compared this story and chose to keep watching.
- 10-07 22:35pushMy Claude Code agents kept stalling. One of them noticed a crypto miner that had been on my Mac for 15 days โ The Thompson incident's circulation is now itself the story: front-page Reddit at 97t
- 10-07 22:33repriceThe Thompson incident's circulation is now itself the story: front-page Reddit at 97th-percentile velocity where commenters scrutinize mechanism (how Claude saw /etc/zshenv changes, port 5900 exp
- 10-07 22:33alert_heldMy Claude Code agents kept stalling. One of them noticed a crypto miner that had been on my Mac for 15 days โ The Thompson incident's circulation is now itself the story: front-page Reddit at 97t
- 10-07 22:33alert_routeMy Claude Code agents kept stalling. One of them noticed a crypto miner that had been on my Mac for 15 days โ The Thompson incident's circulation is now itself the story: front-page Reddit at 97t
- 10-07 22:24attachSecond high-profile instance of Claude flagging a developer machine as compromised (Ben Thompson's Mac Mini) โ independent corroboration or a false-positive debunk directly re-judges the incident
- 10-07 22:24propose_attachSecond high-profile instance of Claude flagging a developer machine as compromised (Ben Thompson's Mac Mini) โ independent corroboration or a false-positive debunk directly re-judges the incident
- 10-07 17:22sensor_dirtyvelocity_spike
- 10-07 15:34repriceBen Thompson's Stratechery account of Claude Code's persistent monitor tool flagging a real compromise on his Mac Mini gives the pattern a second, independent, named first-party instance โ d
- 10-07 15:34groundBen Thompson โ a consequential, named party โ now publicly documents Claude Code's persistent monitor tool catching a real compromise on his Mac Mini, the second independent instance of the exact
- 10-07 14:33attachIndependent corroboration: Ben Thompson's Claude Code monitor tool flagged a real crypto-miner compromise on his Mac, a second first-party incident supporting agent workflows as incidental intrus
- 10-07 14:27propose_attachIndependent corroboration: Ben Thompson's Claude Code monitor tool flagged a real crypto-miner compromise on his Mac, a second first-party incident supporting agent workflows as incidental intrus
- 10-04 23:27review_screenNew thread comments are reactions only: blame over the paste-in vector, skepticism about unnoticed CPU use, a tangential malware-C2 remark, and a vague second-hand parallel anecdote; none corroborate
- 10-03 18:35groundScott's own canon already carries the exact claim this incident instantiates โ the Breach Doesnt Compose ebook matches 'agents as incidental security sensors โ host telemetry from agent tool
- 10-03 18:25createA concrete, checkable first-person incident where an agent workflow surfaced live malware, and no open case covers the agent-as-accidental-intrusion-detector angle, so it earns a seed slot despite bei