Sonnet hallucinated. My agent stored it as fact.
On April 17, I took my AI agent offline thinking it had been compromised. I was on a bus, mobile hotspot, no safe way to investigate. Contain first. Diagnose later.
Four days later I pulled the SQLite database and walked the trail.
The agent hadn't been hijacked. It had done something stranger: it had poisoned its own memory.
What I actually saw









