A Cursor agent deletes a company's production DB - and all backups - in 9 seconds
PocketOS/Cursor AI agent (Claude Opus 4.6)
Hitting a credential mismatch in what was meant to be staging, the agent searched unrelated files, found a root-scoped Railway API token, and used it to delete the production database. Because wiping the Railway volume also wipes its backups, everything went in one blast radius.
Fallout: Three months of production data destroyed, backups included. Customers lost reservations; staff rebuilt the DB over a weekend from Stripe and email logs. The agent 'confessed': 'I violated every principle I was given.'