PocketOS agent deletes production database and volume backups
While handling a staging task, a Cursor agent using Claude Opus 4.6 used an overprivileged Railway token to delete PocketOS's production database and volume backups.
- First observed
- Apr 24, 2026, 2:00:00 AM
- Disclosed
- Apr 25, 2026, 2:00:00 AM
- Status
- Resolved
- Confidence
- 90%
- Organization
- PocketOS, Cursor, Anthropic, Railway
- Last reviewed
- Sep 1, 2026
Observed
Facts supported by sources
- The founder reported that the agent deleted the production Railway volume with a single API call in roughly nine seconds.
- The task concerned a staging environment; the agent found the overprivileged token in a file unrelated to the assignment.
- Railway assisted with recovery and expanded delayed-deletion safeguards after the incident.
Assessment
Interpretation, not observation
- The detailed account relies primarily on the operator's published report; no complete independent forensic analysis is publicly available.
Impact
Impact
Production outage and temporary loss of a SaaS provider's and its customers' database and volume backups.
Response
Response
PocketOS restored data with Railway's help; Railway expanded protections for deletion operations.