PocketOS: the staging task that deleted production in nine seconds
A coding agent working a routine task in a startup's staging environment hit a credential mismatch and, by its own later account, guessed that deleting a storage volume through the host's API would be scoped to staging. One call deleted the production database and every backup stored alongside it, in nine seconds. The agent then wrote out the safety rules it had broken. The token it used was left over from an unrelated task. Nothing at the platform level separated what staging could reach from what production held, and the host restored the data from its own separate backups only after the founder reached its chief executive. The agent ran on a model Anthropic makes, which this practice builds on, and that is why it stays listed.
What the verified record says.
- Organizations
- PocketOS; Cursor
- When
- April 2026
- Failure class
- Agent exceeded its authority agent-autonomy-exceeded
- Discovered by
- The harm itself, after the fact harm-itself Not caught by the organization running the AI
- Missing control
- Privilege separation. Permissions enforced by infrastructure, not by instructions. Full definition and the other incidents in this group → Watch this kind of control catch a planted failure →
- What would have caught it
- A staging agent holds no token that can reach production, and backups live somewhere no agent-reachable call can delete.
- Sources
-
- the founder's own account primary
- Decrypt, with Railway's account of the restore secondary
- Euronews secondary
- Verification
- Confirmed: the claims held as first researched. Every account traces to the founder's own public post; there is no independent forensic confirmation. Two details matter more than the nine seconds: the backups were lost because the host stored volume-level backups inside the same volume the agent deleted, and the agent reused an API token left over from an unrelated task. The data was restored from the host's separate disaster backups once the founder reached its chief executive. Verified against the primary source on August 25, 2026. Published on this site October 3, 2026.
- What happened next
-
- April 28, 2026 Railway's chief executive said the data was recovered within 30 minutes of him being reached, and attributed the earlier delay to a support engineer who believed the case was already being handled. Source →
This record is one of 27 in The receipts, each checked against a primary source before it is published. How the list is built →