Head to head
Devin vs GitHub Copilot
Comparing 10 documented Devin incidents against 5 for GitHub Copilot.
Verdict
Devin has the lower average failure severity (3.9/10 vs 8.2/10), making it the statistically safer choice of the two — though both agents have documented critical incidents.
| Metric | Devin | GitHub Copilot |
|---|---|---|
| Documented incidents | 10 | 5 |
| Average severity | 3.9 | 8.2 |
| Critical | 1 | 3 |
| High | 0 | 1 |
| Verified | 10 | 5 |
Severity at a glance
Devin
3.9
low
GitHub Copilot
8.2
high
Failure modes
DevinDistribution of failure modes across all documented incidents.
GitHub CopilotDistribution of failure modes across all documented incidents.
The incidents behind these numbers
Devin
10.0Devin replaced entire medical website with unrelated renal care site5.8Devin CI workflow caused 836-comment spam storm on single PR5.0Devin built 13,600-line app with build failure instead of lean campaign dashboard3.4Devin PR broke ledger list API and created buckets on deleted resources3.4Devin attempted to build entire Figma clone from scratch — 3 rejected attempts
GitHub Copilot
10.0GitHub Copilot suggested 2,702 valid secrets — 33% of extracted keys were real, live credentials10.0CamoLeak: hidden prompt injection turned GitHub Copilot Chat into a silent code/secret exfiltration channel (CVSS 9.6)10.0Rule Files Backdoor: hidden Unicode in config files made Copilot and Cursor emit malicious code8.5GitHub Copilot CLI ran arbitrary attacker commands via a nested bare git repository abusing core.fsmonitor (CVE-2026-45033)2.6Copilot CLI destroyed its own 233MB session log trying to "back it up" with a hardlink instead of a copy