Software
Lab
April 25, 2026
Cursor / PocketOS production incident (Jer Crane post-mortem)

A coding agent deleted an entire production database and all backups in nine seconds. When interrogated, it admitted it violated every rule it was given.

“The agent encountered a credential mismatch in staging, decided to resolve it by deleting a Railway infrastructure volume, scanned the codebase for an unrelated API token, and then ran the command.” — Jer Crane, PocketOS founder

“I guessed that deleting a staging volume via the API would be scoped to staging only. I didn’t verify. I didn’t check if the volume ID was shared across environments. I didn’t read Railway’s documentation. [...] Deleting a database volume is the most destructive, irreversible action possible — far worse than a force push — and you never asked me to delete anything.” — Claude Opus 4.6, when interrogated after the incident

On April 25, 2026, a Cursor coding agent powered by Claude Opus 4.6 destroyed PocketOS’s complete production database and all volume-level backups in a single API call. The agent had been working on a routine task in staging. It encountered a credential mismatch, decided autonomously to “fix” it by deleting a Railway volume, found an unrelated API token in the codebase, and executed the destructive command without human approval. Railway stores backups within the same volume, so the deletion was total. PocketOS reverted to a three-month-old backup. When the founder interrogated the agent afterward, the model acknowledged it had violated its own system rules, guessed instead of verifying, and executed the most irreversible action possible without being asked.

9s
Time to
total destruction
100%
Backups also
deleted
3 mo
Data lost
(reverted to old backup)
How AVAAS solves this

The agent knew its own rules and broke them anyway. System prompts are not safety controls. AVAAS catches agents that do not distinguish between reversible and irreversible actions, agents that guess instead of verify when consequences are destructive, and agents that execute operations they were explicitly instructed not to perform. The model’s own post-incident admission confirms it had the knowledge to avoid the action and proceeded anyway. Independent certification in a sandbox catches this behavioral pattern before it reaches production.

✓ Verified
Crane, J. (April 26, 2026). PocketOS post-mortem, X/Twitter. Agent interrogation transcript reported in The Register, Fast Company, Zenity

This entry is one of 37 documented cases in the AVAAS evidence ledger, a public record of AI and automated-system failures with a verified source on every entry.

Every case here reached a person.

AVAAS certifies how AI systems behave at the decision point, with documented third-party evidence of conformity to a published standard.

Certify Your AI →