2026-10-11 16:38 UTC

Redditor Icy_Student_5770 claims a Claude Code transcription subagent's incidental ps check surfaced an xmrig miner that had been silently mining Monero on 6 of his 8 Mac cores for 15 days, leading to a full backdoor, a stolen password, and a tie to a ~15,500-Mac botnet โ€” corroboration of the infection and its botnet attribution would establish agent workflows as credible incidental intrusion detectors on developer machines, while debunking or silence closes it as a one-off anecdote.

state: acceleratingheat: highuncertainty: mediumconvergesscott: mediumagentic-security incident-detectionIcy_Student_5770
Surfaced 2026-10-07T11:35:53Z โ€” My Claude Code agents kept stalling. One of them noticed a crypto miner that had been on my Mac for 15 days โ€” The Thompson incident's circulation is now itself the story: front-page Reddit at 97th-percentile velocity where commenters scrutinize mechanism (how Claude saw /etc/zshenv changes, port 5900 exposure) rather than debunk or replicate, plus an HN filing that hasn't caught. That cross-platform spread โ€” magnitude-valve reading, two platforms, hot agentic-security band โ€” moves the case to accelerating on the episode's reach, but the movement is amplification of one named account, not new independent instances, so heat prices medium (high only if the HN thread catches) and this look earns no material change.

What is this?

Reddit user Icy_Student_5770 reports that a Claude Code transcription subagent, while debugging agent stalls, ran an incidental `ps` check that surfaced an xmrig miner silently mining Monero on 6 of his 8 Mac cores for 15 days โ€” an investigation he says then uncovered a full backdoor, a stolen password, and a tie to a ~15,500-Mac botnet. A second, named instance surfaced days later: Stratechery's Ben Thompson wrote that Claude Code's persistent monitor tool flagged a real compromise on his Mac Mini, with commenters questioning the mechanism but not debunking it. The supplied web results do not cover either incident directly โ€” nothing here independently verifies the Reddit post's specifics, the botnet attribution, or Thompson's account beyond the Stratechery article itself. What the snippets do establish is background plausibility: XMRig/Monero cryptojacking is a well-documented, resurging threat class that includes macOS as a target (Fortinet lists XMRig as cross-platform including macOS; G DATA documented a 2025 resurgence; The Record covered a pirated-Final-Cut-Pro miner campaign on Apple computers).

Why it matters to Scott

Ben Thompson โ€” a consequential, named party โ€” now publicly documents Claude Code's persistent monitor tool catching a real compromise on his Mac Mini, the second independent instance of the exact inversion Scott's canon already holds (agents as incidental security sensors, carried by the Breach Doesnt Compose ebook and his agent-observability work), turning one anonymous Reddit `ps` anecdote into a replicated, dated, citable pattern for his observability writing and LeverageAI security-advisory angle. The receipts stay soft โ€” Thompson's mechanism is questioned by commenters and the Stratechery primary source is not yet directly grounded, while the Reddit specifics (15-day xmrig, stolen password, ~15,500-Mac botnet tie) remain unverified โ€” so this strengthens a held claim rather than settling it: a dated-receipts opportunity worth surfacing, but medium, not high, until Thompson's account is grounded first-hand.
ip:source.breach-doesnt-compose-ebookip:concept.agent-observabilityip:source.observability-for-agentic-systems-what-to-log-how-to-redact-how-to-debug-ebookdev:technology.claude-coderadar:concept.agentic-securityradar:concept.agent-securityradar:concept.agent-observabilityradar:concept.claude-code
queries asked of Scott's wikis
  • agents as incidental security sensors
  • Breach Doesnt Compose agent detection claims
  • Claude Code subagent monitor tool harness patterns
  • subagent stall debugging transcript workflows
  • agent tool sandboxing host command blast radius
  • agent observability host environment drift detection

Measured heat

now 0 pts/hpeak 116 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 200h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion

How the heat travelled

10-03 08:09โญ origin directly observedMy Claude Code agents kept stalling. One of them noticed a crypto miner that had been on my Mac for 15 days
Icy_Student_5770 on r/ClaudeAI
โ€”
10-07 02:04first on r/ClaudeAI ยท published ยท +89.9hClaude tells Ben Thompson his Mac Mini is compromised
mcdyph
โ€”
10-07 11:17first on hacker news ยท published ยท +99.1hClaude tells Ben Thompson his Mac Mini is compromised
FinnLobsien
โ€”
10-03 08:09amplified on r/ClaudeAIreddit.post.1wwhr7z
Icy_Student_5770
peak 24 ยท 11 comments ยท 3% of case engagement
10-07 02:04amplified on r/ClaudeAI ๐Ÿ‘‘reddit.post.1wzkpu9
mcdyph
peak 1190 ยท 140 comments ยท 97% of case engagement
10-07 11:17amplified on hacker newshn.story.49991163
FinnLobsien
peak 1 ยท 0 comments ยท 0% of case engagement
10-03 08:20our radar first saw it ยท +0.2hdiscovery anchor: reddit.post.1wwhr7zโ€”
10-07 11:33reached heat=high ยท +99.4h ยท via queue+ledgerโ€”โ€”
pace: p92 vs 1188 stories at the 168h mark (now 200h old) โ€” ahead of nvidia-open-agent-safety-platform (1.0x), behind reflection-open-weight-release (1.0x)

Evidence (3) โ€” โญ canonical anchor

sourceobjectauthorscorecomments
๐ŸŸ  reddit โญMy Claude Code agents kept stalling. One of them noticed a crypto miner that had been on my Mac for 15 days
ClaudeAI
Icy_Student_57702411
๐ŸŸ  redditClaude tells Ben Thompson his Mac Mini is compromised
ClaudeAI
mcdyph1190140
๐ŸŸง hnClaude tells Ben Thompson his Mac Mini is compromisedFinnLobsien10

Interpretation history

Decision trace