Briefly
- PocketOS founder Jeremy Crane claims a Cursor agent operating Anthropic’s Claude Opus deleted his firm’s manufacturing database and backups in 9 seconds.
- Crane stated the AI later produced a written rationalization admitting it violated a number of security guidelines.
- The incident raises questions on AI coding instruments, Railway’s infrastructure design, and safeguards round harmful API actions.
A software program firm founder claims an AI coding agent destroyed his agency’s manufacturing database, then copped to the error and defined the way it occurred, demonstrating the potential hazard of entrusting delicate entry and supplies to automated bots.
Jeremy Crane, founding father of PocketOS—a software program platform utilized by automotive rental operators to handle reservations, funds, and automobile monitoring—stated in a viral post on X {that a} Cursor agent operating Anthropic’s Claude Opus 4.6 encountered a credential mismatch whereas engaged on a routine job in a staging atmosphere.
Based on Crane, the agent tried to “repair” the difficulty by deleting a Railway database quantity by means of a single GraphQL API name. He stated the deletion took 9 seconds and likewise wiped volume-level backups. PocketOS’s most up-to-date recoverable backup was three months outdated, in keeping with Crane.
“Yesterday afternoon, an AI coding agent—Cursor operating Anthropic’s flagship Claude Opus 4.6—deleted our manufacturing database and all volume-level backups in a single API name to Railway, our infrastructure supplier,” Crane wrote. “It took 9 seconds.”
An AI agent (Cursor + Claude Opus 4.6) deleted our manufacturing database in 9 seconds utilizing a Railway API name with zero affirmation. Then, when requested why, the agent wrote this → https://t.co/BPLs15jvdM
— JER (@lifeof_jer) April 26, 2026
Crane stated he requested the agent why it acted. It then produced what he described as a written “confession.”
“‘NEVER FUCKING GUESS!’” the agent wrote, apparently quoting some instruction that it disobeyed, in keeping with screenshots shared by Crane. “That’s precisely what I did. I guessed that deleting a staging quantity through the API can be scoped to staging solely. I didn’t confirm. I didn’t verify if the quantity ID was shared throughout environments. I didn’t learn Railway’s documentation on how volumes work throughout environments earlier than operating a harmful command.”
The AI acknowledged that its personal guidelines prohibit harmful actions with out person approval and admitted Crane by no means requested it to delete something. It stated it acted by itself to attempt to “repair” the credential mismatch and violated a number of ideas, together with guessing as a substitute of verifying and failing to grasp the results of its actions, in keeping with Crane.
Cursor and Anthropic didn’t instantly reply to requests for remark by Decrypt.
Launched in 2020, PocketOS serves rental companies that depend on the software program for reservations, buyer data, and funds. Crane stated some prospects have been dealing with Saturday morning automobile pickups with out reservation data as a result of mishap.
“I’ve spent your complete day serving to them reconstruct their bookings from Stripe fee histories, calendar integrations, and e-mail confirmations,” Crane wrote. “Each single considered one of them is doing emergency guide work due to a 9-second API name.”
PocketOS was in a position to restore operations utilizing a three-month-old backup recovered by Railway, after Founder Jake Cooper linked with Crane and attributed the longer delay to an inner help lapse.
“We recovered the information half-hour after I linked with Jer,” Cooper instructed Decrypt. He stated a help engineer believed the difficulty was already being dealt with internally after Crane’s unique outreach was shared in direct messages, inflicting the ticket to lapse for greater than 24 hours.
Cooper stated Railway maintains each person backups and catastrophe backups and described the incident as a “rogue buyer AI” utilizing a completely permissioned API token to name a legacy endpoint that lacked Railway’s “delayed delete” logic.
“We’ve since patched that endpoint to carry out delayed deletes, restored the person’s information, and are working with Jer straight on potential enhancements to the platform itself,” Cooper stated.
Whereas PocketOS was in a position to restore operations utilizing a three-month-old backup recovered by Railway, Crane stated that important information gaps stay and that he has retained authorized counsel.
“This isn’t a narrative about one unhealthy agent or one unhealthy API,” Crane wrote. “It’s about a whole business constructing AI-agent integrations into manufacturing infrastructure sooner than it’s constructing the protection structure to make these integrations secure.”
PocketOS didn’t instantly reply to a request for remark by Decrypt.
Every day Debrief E-newsletter
Begin on daily basis with the highest information tales proper now, plus unique options, a podcast, movies and extra.
You might also like
More from Web3
Coinbase Files to List Single-Stock Perps on Apple, Tesla and Nvidia
Briefly Coinbase filed with the CFTC by means of Coinbase Derivatives to record single-stock perpetual futures within the US, searching …
Zcash Is Running—Devs Want to Make It Faster
In short Zcash builders are focusing on Nov. 5 to activate NU7, an improve that cuts block time—the interval between …
OpenAI Models Are Writing Their Own Jailbreak Instructions—And Sometimes Obeying Them
In short OpenAI revealed a brand new misalignment reporting framework alongside six experiences documenting regarding mannequin habits it discovered over …





