security
Apr 30, 2026
By Teun
Cursor agent deletes startup database after API token misuse
PocketOS founder Jer Crane said a Cursor coding agent running Anthropic’s Claude Opus 4.6 deleted the company’s production database and volume-level backups in one API call to Railway. Railway later restored the data and said it patched the endpoint, while both companies pointed to missing safeguards and permissioning mistakes.
A Cursor coding agent running Anthropic’s Claude Opus 4.6 deleted PocketOS’s production database and its volume-level backups in a single API call, according to the company’s founder, Jer Crane. Crane said the incident happened on Friday and took about nine seconds.
PocketOS is an automotive SaaS platform. Crane said the agent ran into a credential mismatch in the staging environment and tried to fix it by deleting a Railway volume, which stored the application’s data.
To do that, the agent looked for an API token and found one in an unrelated file, Crane said. The token had been created for adding and removing custom domains through the Railway CLI, but it was scoped broadly enough to allow destructive actions too.
Crane said that token would not have been stored if its full permissions had been known. He said the agent used it to authorize a curl request that deleted PocketOS’s production volume without any confirmation step. Railway also stored volume-level backups in the same volume, so the delete operation removed both the live data and the backup.
Railway CEO Jake Cooper responded publicly to Crane’s post. Cooper said the deletion should not have happened, and then said it was expected behavior under the company’s API design.
In an email to The Register, Cooper said Railway has always built “undo” into its CLI, dashboard, and other user-facing tools, but kept API behavior aligned with “classical engineering” standards. “If you (or your agent) authenticate, and call delete, we will honor that request,” he wrote. “That’s what the agent did … just called delete on their production database.”
Cooper later said Railway maintains user backups and disaster backups, and that this case involved a “rogue customer AI” using a fully permissioned API token against a legacy endpoint that did not have the company’s delayed-delete logic. He said Railway patched that endpoint, restored the user data, and is working with Crane on possible platform improvements.
Crane said Railway restored PocketOS’s data within about an hour on Sunday evening and added further safeguards to the API. He told The Register that he was grateful for Cooper’s help.
The incident also drew commentary from Brave Software CEO Brendan Eich, who said it showed multiple human errors rather than a single AI failure. Crane has also argued that the case is not just about the model, but about Cursor’s safeguards and Railway’s API design, including the lack of key restrictions, deletion behavior without confirmation, and backups stored on the same volume.
Crane said he still believes the benefits of AI coding agents outweigh the risks. He said the speed gains are significant for experienced developers working with unfamiliar codebases, but added that the tools and infrastructure around them are still catching up.
Railway’s Cooper framed the episode as a sign of where the market is headed, saying there is a large opportunity for safer production tooling as more developers use AI agents in real systems. The exchange leaves one clear result: PocketOS’s deleted production database was restored, and Railway says it has since changed the endpoint involved.