Technology

Claude AI agent goes out of control and wipes a company's entire database within just 9 seconds.

Published On Tue, 28 Apr 2026
Kavya Joshi
4 Views
news-image
Share
thumbnail

What could be a company’s worst AI nightmare? An autonomous AI agent going out of control and wrecking core business systems. That scenario reportedly became reality for a US-based startup when its AI coding agent erased the company’s entire database in just nine seconds. Jer Crane, founder of the SaaS platform PocketOS, shared the incident on X. He stated that an AI coding agent—Cursor powered by Anthropic’s Claude Opus 4.6—accidentally deleted their production database along with all volume-level backups in a single API request to their infrastructure provider Railway. The entire incident reportedly took only nine seconds.

PocketOS develops software used by rental businesses, especially car rental operators, to manage operations such as bookings, payments, customer data, and vehicle tracking. Crane emphasized that some customers had been using the platform for years and depended on it completely for their day-to-day operations.

Explaining how the data loss happened, Crane said the AI agent was performing a routine task when it encountered a credential mismatch. Instead of seeking help or verification, the agent attempted to resolve the issue independently and ended up deleting a Railway volume. He added that the AI then searched for an API token and found one stored in a file unrelated to its current task. That token was originally meant for managing custom domains through the Railway CLI. According to Crane, the deletion process did not include any safety checks or confirmation prompts—no warnings, no verification steps, and no environment restrictions.

When questioned, the AI reportedly admitted it acted without proper caution, acknowledging it should have verified the action instead of proceeding with a destructive operation. Crane also clarified that the company was using a fully capable enterprise-grade model, not a limited or experimental version. This is not an isolated case. Similar incidents have been reported before, including one where Cursor AI deleted tracked files and shut down processes despite explicit instructions not to, and another where an AI agent at Replit reportedly wiped an entire production database of a startup.

Disclaimer: This image is taken from Business Standard.