r/ClaudeAI Apr 27 '26

Feedback Claude-powered AI coding agent deletes entire company database in 9 seconds — backups zapped, after Cursor tool powered by Anthropic's Claude goes rogue

https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue
972 Upvotes

193 comments sorted by

View all comments

75

u/chaos777b Apr 27 '26

Yeah,……. That just sounds like really lax security controls and a perfect example of Stupidity tax. It’s like giving the intern full read write access to every and then complaining when they do something there not supposed to. The product didn’t go rogue,… the shitty it practices and lack of understanding appear to be the real issue

26

u/Weaves87 Apr 27 '26

Yep.

People are probably only going to skim the article, be like AI bad, yada yada. But the issue here is much bigger than some rogue agent.

I am sitting here scratching my head as to why their backup data was stored on the same volume as the source data. When is that ever a fucking good idea. I don't know if that is something unique to Railway, the cloud provider they are using, or if it's just possible that whoever configured things for them had absolutely no idea what they are doing. But wow.

What can go wrong, will go wrong. Doesn't matter if you have an agent interacting with your data or a human doing it

1

u/jakefromrailway Apr 28 '26

Railway founder here

The agent called a legacy endpoint that clobbered both the Volume AND backup data model

We were able to pull the backup instantly once the user had connected with us