block #0001 in --:--:--Join the pool
PENDING…
ai pending 5/6 1h ago · 6 min read

PixelLeak is a pile of internal screenshots agents left on public GitHub

PixelLeak is the public trail of a Glow report: coding agents dropped internal screenshots into GitHub repos, and two newsrooms wrote it up from Glow's account. The counts match in outline and not in every detail. Both pieces rely on Glow.

pending 5/6 — still in the mempool

Early story. Some claims here are not officially confirmed yet. We update this post as it confirms.

PixelLeak is a pile of internal screenshots agents left on public GitHub
in this block
  1. What actually happened
  2. What to do as a reader
  3. What you should not add

PixelLeak, as covered here, is Glow's finding that coding agents left internal screenshots in public GitHub repos. The Hacker News wrote it up on September 30, 2026, pointing at a Glow write-up dated September 29. Tom's Hardware is dated October 1, 2026.

TL;DR - On PixelLeak, the Hacker News says Glow found more than 13,000 internal images from developers at over 300 organizations, including billing records and unreleased-feature screens, mostly under personal GitHub accounts. - Tom's Hardware says 13,000-plus screenshots from 300-plus organizations, including Fortune 500 companies and a frontier AI lab, with 93% of images under the developer's personal username. - On PixelLeak, in cases The Hacker News describes, agents used a public repo because, until September 1, GitHub's gh CLI could not attach images to a pull request. gh 2.99.0 that day added an attach flag.

What actually happened

Both outlets are passing on Glow. Neither is an independent census of the repos, and Glow has not said, in Tom's Hardware's account, whether outsiders downloaded the files.

On PixelLeak, Glow is the source of the finding, and the calendar around it is more useful than a single scary total. The Hacker News says Glow began contacting organizations on September 9 and published on September 29. That is a gap of weeks between first outreach and the public write-up, which matters if you are trying to remember whether your company would have heard before the headlines. The headline cycle in this pack is September 30 at The Hacker News and October 1 at Tom's Hardware.

The Hacker News's count is more than 13,000 internal images, from developers at over 300 organizations. The examples it names are billing records and screens of unreleased features. It says the images were mostly under personal GitHub accounts.

On PixelLeak, "Mostly" is that outlet's word. It is not a percentage. About a third of affected organizations had developers using gitshot, in the same account. Scope here is organizations, not a loose "a third of the pictures."

Tom's Hardware's count is 13,000-plus screenshots from 300-plus organizations. It adds that the list includes Fortune 500 companies and a frontier AI lab. It does not, in the material used here, name those companies or that lab, so this piece will not invent names.

On PixelLeak, about a third used gitshot, which is a slightly different "about a third" than The Hacker News's line about affected organizations. Tom's Hardware also says 93% of images were in repos under the developer's personal username.

Those personal-account lines point the same direction and still should not be mashed into one statistic. "Mostly" and "93%" are not the same sentence. Over 300 and 300-plus are compatible shapes, not a merged census.

On PixelLeak, more than 13,000 and 13,000-plus are the same kind of floor, reported by two outlets that both rely on Glow. Agreement on a floor is not two investigations.

The mechanism The Hacker News describes is painfully ordinary. In the cases reviewed, agents put screenshots in a public repo because, until September 1, GitHub's gh CLI could not attach images to a pull request. gh 2.99.0 on September 1 added an attach flag.

On PixelLeak, an agent that was told, in effect, to get the picture onto the review thread used the path that existed. The path that existed was a commit the internet could see. That is the failure mode, and it does not require a mastermind.

What to do as a reader

If you run coding agents, treat a screenshot as a secret until you have a reason not to. Billing records and unreleased-feature screens are the examples The Hacker News gives, which is already enough to stop using "it's just a UI grab" as a comfort. The practical check is your own repos, especially repos under personal usernames.

On PixelLeak, both outlets stress that personal-account pattern. An org policy that only scans organization-owned repos is aimed at the wrong shelf.

Do not go hunting other people's leaked images. The story is that internal pictures were public, not that the internet now has a scavenger-hunt assignment. Tom's Hardware says Glow has not said whether anyone outside the companies and Glow's researchers downloaded the files.

On PixelLeak, that uncertainty cuts both ways. You cannot honestly claim "nobody else saw them," and you also cannot honestly claim a confirmed mass download. Leave the files alone if they are not yours.

Ask a local question instead. Were we among the organizations Glow started contacting on September 9. Did a developer on our team use an agent that commits images.

On PixelLeak, did anyone use gitshot. About a third of affected organizations had developers using gitshot, per The Hacker News, and Tom's Hardware says about a third used gitshot. Either way, gitshot is a clue, not the whole population. Two thirds, in that "about a third" framing, are not explained by that tool alone, and this pack does not name the other tools.

Updating the CLI is hygiene, not cleanup. The Hacker News ties the reviewed cases to a period when gh could not attach images, and to gh 2.99.0 on September 1 adding that flag. Installing a newer CLI does not unpublish a file that is already in a public history.

On PixelLeak, if a screenshot landed in a repo, the work is history rewriting or deletion plus rotation of anything the image shows, done by the people who own the data. This article is not a tutorial for scraping those repos, and it will not become one.

Assume the write-ups are only as strong as Glow. Both rely on Glow. There is no second primary dataset in this pack, no list of the 300 organizations, and no statement from GitHub quoted here.

On PixelLeak, Fortune 500 companies and a frontier AI lab are Tom's Hardware's additions to the outline. Billing records, unreleased-feature screens, the September 9 contact start, and the gh CLI timeline are The Hacker News's. Keep the attributions glued to the details.

What you should not add

Do not add company names, download counts, or a claim that the attach flag fixed the past. Do not treat 93% and "mostly" as one number you measured. Do not read "a frontier AI lab" as permission to guess which lab. The absence of names in the pack is a limit, not a puzzle.

On PixelLeak, a useful internal note is short. Agents plus screenshots plus a public default is a bad combination, and personal repos were the common shelf in both stories. The CLI gap The Hacker News describes explains the cases it reviewed.

It does not explain every image, and it does not tell you whether strangers downloaded anything. Glow's silence on that download question, as Tom's Hardware reports it, stays in the note.

On PixelLeak, if you are briefing non-specialists, skip the spy-movie framing. The reported path is an agent doing a clumsy thing with a tool limitation, in public, under a personal username. That is still serious, because billing screens and unreleased features do not become harmless by being clumsy. Serious and cinematic are not the same adjective.

The accounts to read are The Hacker News and Tom's Hardware. When they differ, keep both lines. When they match, remember they are both leaning on Glow.

Readers who want sourced recaps that are already on the site can read DogeOS public testnet and PUMP token buyback burn as separate live posts.

Not financial advice. DYOR, ser.

More in the pool

all ai
gm ser

Get confirmed before the crowd

Daily block at 07:00 UTC. No spam, just the block, ser.