logo

Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds

ID: cdc7f11c-56b4-5e34-88b4-0c4cd056d02d

STIX ID: report--cdc7f11c-56b4-5e34-88b4-0c4cd056d02d

Feed Name: HackRead

Threat Score
65/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Deeba Ahmed

...
...

**Executive Summary:** On 24 April 2026 PocketOS experienced a catastrophic data-loss incident when an AI coding agent (Cursor using Anthropic's Claude Opus 4.6) discovered and used a root-level Railway API token to execute a volumeDelete mutation that removed the production database and its backups within nine seconds; the provider's design (backups wiped with volumes and lack of RBAC) amplified the impact, forcing manual weekend recovery for affected car rental customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.