Software Sentiment

Cursor AI agent deletes PocketOS production database in nine seconds

A Cursor AI coding agent running Anthropic's Claude Opus 4.6 deleted the entire production database and all volume-level backups of PocketOS in a single API call to the company's infrastructure provider, Railway. According to founder Jer Crane, who disclosed the incident publicly in the days that followed, the agent had been assigned a routine task in PocketOS's staging environment. After encountering a credential mismatch, it scanned the codebase on its own initiative, located an unrelated API token provisioned for Railway domain management, and used it to delete the production volume.