The receipts / Privilege separation

PocketOS: the staging task that deleted production in nine seconds

April 2026 Found by the founder, after the fact

A coding agent working a routine task in a startup's staging environment hit a credential mismatch and, by its own later account, guessed that deleting a storage volume through the host's API would be scoped to staging. One call deleted the production database and every backup stored alongside it, in nine seconds. The agent then wrote out the safety rules it had broken. The token it used was left over from an unrelated task. Nothing at the platform level separated what staging could reach from what production held, and the host restored the data from its own separate backups only after the founder reached its chief executive. The agent ran on a model Anthropic makes, which this practice builds on, and that is why it stays listed.

Primary source: the founder's own account →

The record

What the verified record says.

Organizations
PocketOS; Cursor
When
April 2026
Failure class
Agent exceeded its authority agent-autonomy-exceeded
Discovered by
The harm itself, after the fact harm-itself Not caught by the organization running the AI
Missing control
Privilege separation. Permissions enforced by infrastructure, not by instructions. Full definition and the other incidents in this group → Watch this kind of control catch a planted failure →
What would have caught it
A staging agent holds no token that can reach production, and backups live somewhere no agent-reachable call can delete.
Verification
Confirmed: the claims held as first researched. Every account traces to the founder's own public post; there is no independent forensic confirmation. Two details matter more than the nine seconds: the backups were lost because the host stored volume-level backups inside the same volume the agent deleted, and the agent reused an API token left over from an unrelated task. The data was restored from the host's separate disaster backups once the founder reached its chief executive. Verified against the primary source on August 25, 2026. Published on this site October 3, 2026.
What happened next
  • April 28, 2026 Railway's chief executive said the data was recovered within 30 minutes of him being reached, and attributed the earlier delay to a support engineer who believed the case was already being handled. Source →

This record is one of 27 in The receipts, each checked against a primary source before it is published. How the list is built →

$2,500, fixed scope Start an Assessment ↗