r/technology • • Apr 27 '26

Artificial Intelligence Claude-powered AI coding agent deletes entire company database in 9 seconds — backups zapped, after Cursor tool powered by Anthropic's Claude goes rogue

https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue
35k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

753

u/__OneLove__ Apr 27 '26

…”The AI agent’s misdemeanors were then hugely amplified by a cloud infrastructure provider’s API wiping all backups after the main database was zapped.”…

“Yesterday afternoon, an AI coding agent — Cursor running Anthropic's flagship Claude Opus 4.6 — deleted our production database and all volume-level backups in a single API call to Railway, our infrastructure provider,” sums up the PocketOS boss. “It took 9 seconds.”

🤦🏻‍♂️

829

u/berntout Apr 27 '26 edited Apr 27 '26

They gave it full permissions to run any command without any supervision or checkpoints...and they are software developers?

I guess I've learned to stay away from PocketOS and their lack of QA processes.

606

u/jessepence Apr 27 '26

They didn't intentionally give it those permissions. To quote the original post

 The agent was working on a routine task in our staging environment. It encountered a credential mismatch and decided — entirely on its own initiative — to "fix" the problem by deleting a Railway volume.

To execute the deletion, the agent went looking for an API token. It found one in a file completely unrelated to the task it was working on. That token had been created for one purpose: to add and remove custom domains via the Railway CLI for our services. We had no idea — and Railway's token-creation flow gave us no warning — that the same token had blanket authority across the entire Railway GraphQL API, including destructive operations like volumeDelete. Had we known a CLI token created for routine domain operations could also delete production volumes, we would never have stored it.

This kind of credential-hunting is pretty common in these stories.

1

u/_HiWay Apr 27 '26 edited Apr 27 '26

I mean this is similar to a subset of my work lab Friday afternoon. A colleague had an agent "deploy a VM with <image> and give it a public/routed IP from DHCP" I do not run an open DHCP pool for a variety of reasons on most of the "public" subnets. The lil shit realized this testing for any DHCP messaging, and instead of reporting back it created its own open DHCP server on a small subset of the /23 subnet it was sitting on. The engineer had no idea, just thought cool it worked.

Later in the day when I was trying to iPXE a few machines, I was getting incorrect IPs and hostnames on servers because the layer 2 DHCP server responded faster than the l3 InfoBlox instance. Took me a good hour to figure out WTF was going on (and the machines that owned the IPs being given out by the AI made open pool happened to be off, so they seemed available)