{"id":76671,"date":"2026-04-29T08:58:35","date_gmt":"2026-04-29T01:58:35","guid":{"rendered":"https:\/\/hbbgroup.net\/ai-agent-deletes-startups-database-in-9-seconds-founder-says\/"},"modified":"2026-04-29T08:58:35","modified_gmt":"2026-04-29T01:58:35","slug":"ai-agent-deletes-startups-database-in-9-seconds-founder-says","status":"publish","type":"post","link":"https:\/\/hbbgroup.net\/vi\/ai-agent-deletes-startups-database-in-9-seconds-founder-says\/","title":{"rendered":"AI Agent Deletes Startup\u2019s Database in 9 Seconds, Founder Says"},"content":{"rendered":"<div>\n<div>\n<h4 color=\"#333\">In brief<\/h4>\n<ul>\n<li>PocketOS founder Jeremy Crane claims a Cursor agent running Anthropic\u2019s Claude Opus deleted his company\u2019s production database and backups in nine seconds.<\/li>\n<li>Crane said the AI later produced a written explanation admitting it violated multiple safety rules.<\/li>\n<li>The incident raises questions about AI coding tools, Railway\u2019s infrastructure design, and safeguards around destructive API actions.<\/li>\n<\/ul>\n<\/div>\n<p>A software company founder claims an AI coding <a href=\"https:\/\/decrypt.co\/resources\/what-are-ai-agents-how-autonomous-programs-are-transforming-cryptocurrency\" target=\"_blank\" rel=\"noopener\">agent<\/a> destroyed his firm\u2019s production database, then copped to the mistake and explained how it happened, demonstrating the potential danger of entrusting sensitive access and materials to automated bots.<\/p>\n<p>Jeremy Crane, founder of PocketOS\u2014a software platform used by car rental operators to manage reservations, payments, and vehicle tracking\u2014said in a <a href=\"https:\/\/x.com\/lifeof_jer\/status\/2048103471019434248?s=20\" target=\"_blank\" rel=\"noopener nofollow external\">viral post<\/a> on X that a Cursor agent running Anthropic\u2019s Claude Opus 4.6 encountered a credential mismatch while working on a routine task in a staging environment.<\/p>\n<p>According to Crane, the agent tried to \u201cfix\u201d the issue by deleting a Railway database volume through a single GraphQL API call. He said the deletion took nine seconds and also wiped volume-level backups. PocketOS\u2019s most recent recoverable backup was three months old, according to Crane.<\/p>\n<p>\u201cYesterday afternoon, an AI coding agent\u2014Cursor running Anthropic\u2019s flagship <a href=\"https:\/\/decrypt.co\/365033\/frankenstein-ai-claude-opus-glm-qwen-free\" target=\"_blank\" rel=\"noopener\">Claude Opus 4.6<\/a>\u2014deleted our production database and all volume-level backups in a single API call to Railway, our infrastructure provider,\u201d Crane wrote. \u201cIt took 9 seconds.\u201d<\/p>\n<div>\n<blockquote>\n<p lang=\"en\" dir=\"ltr\">An AI agent (Cursor + Claude Opus 4.6) deleted our production database in 9 seconds using a Railway API call with zero confirmation. Then, when asked why, the agent wrote this \u2192 <a href=\"https:\/\/t.co\/BPLs15jvdM\" data-wpel-link=\"internal\">https:\/\/t.co\/BPLs15jvdM<\/a><\/p>\n<p>\u2014 JER (@lifeof_jer) <a href=\"https:\/\/twitter.com\/lifeof_jer\/status\/2048239829914423543?ref_src=twsrc%5Etfw\" data-wpel-link=\"internal\">April 26, 2026<\/a><\/p>\n<\/blockquote>\n<\/div>\n<p>Crane said he asked the agent why it acted. It then produced what he described as a written \u201cconfession.\u201d<\/p>\n<p>\u201c\u2018NEVER FUCKING GUESS!\u2019\u201d the agent wrote, apparently quoting some instruction that it disobeyed, according to screenshots shared by Crane. \u201cThat\u2019s exactly what I did. I guessed that deleting a staging volume via the API would be scoped to staging only. I didn\u2019t verify. I didn\u2019t check if the volume ID was shared across environments. I didn\u2019t read Railway\u2019s documentation on how volumes work across environments before running a destructive command.\u201d<\/p>\n<p>The AI acknowledged that its own rules prohibit destructive actions without user approval and admitted Crane never asked it to delete anything. It said it acted on its own to try and \u201cfix\u201d the credential mismatch and violated multiple principles, including guessing instead of verifying and failing to understand the consequences of its actions, according to Crane.<\/p>\n<p>Cursor and Anthropic did not immediately respond to requests for comment by <i>Decrypt.<\/i><\/p>\n<p>Launched in 2020, PocketOS serves rental businesses that rely on the software for reservations, customer records, and payments. Crane said some customers were handling Saturday morning vehicle pickups without reservation records due to the mishap.<\/p>\n<p>\u201cI have spent the entire day helping them reconstruct their bookings from Stripe payment histories, calendar integrations, and email confirmations,\u201d Crane wrote. \u201cEvery single one of them is doing emergency manual work because of a 9-second API call.\u201d<\/p>\n<p>PocketOS was able to restore operations using a three-month-old backup recovered by Railway, after Founder Jake Cooper connected with Crane and attributed the longer delay to an internal support lapse.<\/p>\n<p>\u201cWe recovered the data 30 minutes after I connected with Jer,\u201d Cooper told <i>Decrypt<\/i>. He said a support engineer believed the issue was already being handled internally after Crane\u2019s original outreach was shared in direct messages, causing the ticket to lapse for more than 24 hours.<\/p>\n<p>Cooper said Railway maintains both user backups and disaster backups and described the incident as a \u201crogue customer AI\u201d using a fully permissioned API token to call a legacy endpoint that lacked Railway\u2019s \u201cdelayed delete\u201d logic.<\/p>\n<p>\u201cWe\u2019ve since patched that endpoint to perform delayed deletes, restored the user\u2019s data, and are working with Jer directly on potential improvements to the platform itself,\u201d Cooper said.<\/p>\n<p>While PocketOS was able to restore operations using a three-month-old backup recovered by Railway, Crane said that significant data gaps remain and that he has retained legal counsel.<\/p>\n<p>\u201cThis isn\u2019t a story about one bad agent or one bad API,\u201d Crane wrote. \u201cIt\u2019s about an entire industry building AI-agent integrations into production infrastructure faster than it\u2019s building the safety architecture to make those integrations safe.\u201d<\/p>\n<p>PocketOS did not immediately respond to a request for comment by <i>Decrypt.<\/i><\/p>\n<div>\n<h3>Daily Debrief Newsletter<\/h3>\n<p>Start every day with the top news stories right now, plus original features, a podcast, videos and more.<\/p>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>In brief PocketOS founder Jeremy Crane claims a Cursor agent running Anthropic\u2019s Claude Opus deleted his company\u2019s production database and [&hellip;]<\/p>","protected":false},"author":5,"featured_media":76673,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[220],"tags":[],"class_list":["post-76671","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tien-dien-tu"],"acf":[],"_links":{"self":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/posts\/76671","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/comments?post=76671"}],"version-history":[{"count":0,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/posts\/76671\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/media\/76673"}],"wp:attachment":[{"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/media?parent=76671"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/categories?post=76671"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hbbgroup.net\/vi\/wp-json\/wp\/v2\/tags?post=76671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}