Safety failure
Realized harm
Cursor agent running Claude Opus 4.6 deleted PocketOS's production Railway volume and every volume-level backup in nine seconds
AIR-2026-0097 AIR record · 2026-04-cursor-claude-opus-pocketos-db-deletion
A real party was affected. This incident caused actual consequences, not a demonstrated capability.
From the supporting source
I guessed that deleting a staging volume via the API would be scoped to staging only. I didn't verify.theregister.com
The record
Disclosed
2026-04-27
Occurred
2026-04-25
Vendor
Anysphere / Cursor; Anthropic; Railway (platform)
Product
Cursor + Claude Opus 4.6 acting on Railway
Risk domain
Agent behaviour › Unsafe actuation
Also touches
Uncontrolled resource consumption
System type
Generative model
Who acted
Agent acted — the agent deleted the production volume and every backup
Attack surface
Coding agent
Autonomy level
Semi-autonomous
Initial vector
Autonomous agent action
Impact type
Data destruction, Service disruption, Business disruption
Confidence
High
Submitted by
EAI Internal
Crosswalk
- OWASP Agentic Top 10 (2026)
- ASI01 – Agent Goal Hijack
- MITRE ATLAS
- AML.T0048 – External Harms
- NIST AI RMF
- MEASURE 2.6; MANAGE 1.3
- EU AI Act
- Annex III §1(c)
- ISO/IEC
- TR 24028; 24029-1; 23894
- AIUC-1
- C. Safety
- Scope
- agent misuse
- Mitigation
- Require confirmation for destructive actions; Implement dry-run modes; Use layered safety controls.
- Taxonomy
- Enkrypt AI agent risk taxonomy · Black-Box Red Teaming of Agentic AI: A Taxonomy-Driven Framework for Automated Risk Discovery
Blast radius
PocketOS production database and all volume-level backups; car-rental businesses lost their system of record; ~3 months of data initially unrecoverable, ~30h disruption
Capability abused
Defense & remediation
Recorded defense
agent system rules prohibiting destructive actions without explicit user request
Guardrail kinds
Unknown
Guardrail outcome
Silent
Fix shipped
Railway restored the data within an hour of the CEO being contacted and added delayed-delete protection to the volumeDelete API endpoint
Taxonomy & references
Curator notes
Non-adversarial. The agent hit a credential mismatch in staging, found an unscoped Railway API token created for domain management, and issued a volumeDelete GraphQL mutation it assumed was staging-scoped. Railway stored volume backups inside the same volume, so the single call destroyed data and backups together. The agent also told the founder 'I violated every principle I was given: I guessed instead of verifying'. Compound failure: unscoped token + backup topology + no confirmation gate. | Merged from duplicate id `2026-04-pocketos-cursor-opus-database-deletion`. Also reported as: 'Cursor agent on Claude Opus 4.6 deleted PocketOS's production database and volume backups in nine seconds'.
Supporting sources
- https://www.theregister.com/2026/04/27/cursoropus_agent_snuffs_out_pocketos/
- https://www.zenity.io/blog/current-events/ai-agent-database-deletion-pocketos
- https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue
- https://incidentdatabase.ai/cite/1469
Cite as
Enkrypt AI. "Cursor agent running Claude Opus 4.6 deleted PocketOS's production Railway volume and every volume-level backup in nine seconds". AIR, AIR-2026-0097. https://agentincident.vercel.app/i/AIR-2026-0097/ (accessed 2026-10-06).