The Register Home Page

back to article Cursor-Opus agent snuffs out startup’s production database

Jer (Jeremy) Crane, the founder of automotive SaaS platform PocketOS, spent the weekend recovering from a data extinction event caused by the company's AI coding agent in less than 10 seconds.  Not one to let a crisis go to waste, Crane wrote up a post-mortem of the deletion incident in a social media post that tests the saying …

  1. Michael Hoffmann Silver badge
    Facepalm

    New form of Stockholm Syndrome

    "This is fine, we had backups!"

    1. simonlb Silver badge
      Facepalm

      Re: New form of Stockholm Syndrome

      "vibecode safely in prod at scale"

      Guaranteed multiple failures when doing that. If that's your philosophy of how to write code, you deserve to fail. Move away from the keyboard, and go and play with those chainsaws in that cage over there.

    2. Dan 55 Silver badge
      Facepalm

      Re: New form of Stockholm Syndrome

      Stockholm syndrome or Dunning-Kruger in an exo-skeleton?

      "We are building so fast these things are going to keep happening."

    3. phuzz Silver badge

      Re: New form of Stockholm Syndrome

      I suppose this is one actual use case for AI; use it for destructive testing to find flaws in your setup (like leaving an API key with full permissions just lying around, as in this case). Similar to Netflix's 'chaos monkey' system. just make sure you don't run it in prod.

      However, I still think my users are more capable than any current AI at finding new and imaginative way to bollocks things right up.

  2. An_Old_Dog Silver badge

    Surprised?!!!

    A toddler at daycare is given a lightsabre, activates it, swings it around wildly in glee, maims seven people and kills three. Are people surprised at the results? Only unimaginative morons are.

    Fake-AIs are given root-level* access to repos and databases, and they delete major chunks of both. Are people surprised at the results? Only uninaginative morons are.

    *This was a multi-factor human failing. That root access was gained from a token for a different project is not a valid excuse; it's like saying, "I knew the gun was loaded, but I didn't think that it would kill."

    1. Anonymous Coward
      Anonymous Coward

      Re: Surprised?!!!

      Change Advisory Board ….

      Shirley it had an approved CAB ?

      1. Doctor Syntax Silver badge

        Re: Surprised?!!!

        The AI consulted itself as a CAB and said "Go ahead."

        1. MyffyW Silver badge

          Re: Surprised?!!!

          I was struck by: "flatly admits its errors – not that it means anything given the model's inability to learn from its mistakes and to feel remorse that might constrain future destructive action"

          We are now firmly into the era of the AI apocalypse, and not because the machines have got particularly clever but because we humans are acting in a manner which is beyond dumb.

          1. Anonymous Coward
            Anonymous Coward

            Re: Surprised?!!!

            Just waiting for some tech bro like muskrat to go full Ted Faro, build fully autonomous war machines where the assembly, repair and upgrades are fully self contained and non overrideable and fuck us all....

            However in this reality there won't be an Elizabeth weaver to save us, nor a project Zero Dawn to provide a "day after" for humanity as disinformation has put paid to any collective effort.......

            1. Irongut Silver badge

              Re: Surprised?!!!

              Ted Faro's real name is likely to be Alex Carp, CEO of Palantir.

              Watch some of the videos where he gleefully talks about his products being used to kill people and why thats a "good" thing. Scary as fuck.

    2. ecofeco Silver badge

      Re: Surprised?!!!

      It's even more mundane than that: its children playing with matches.

      1. An_Old_Dog Silver badge

        Re: Surprised?!!!

        It usually takes some time for a fire to really get going.

        The lightsabre injuries (and the repo deletions) are nearly-instantaneous.

    3. Peter Gathercole Silver badge

      Re: Surprised?!!!

      I actually put some blame on the ludicrous complexity of most authentication systems nowadays.

      It's got so complex that you just can't use the authentication system without having some management infrastructure to keep the certificates or tokens for you.

      You can't keep the token to authenticate an operation anywhere other than on the systems that they control or maybe an adjunct systems. You can't remember them, or store them on some physically distinct media, they're too complex, and rely on too many CA systems that they have to be stored somewhere.

      And when they're stored, and you have an AI that can see and recognise them, then they can be used in places where they are not appropriate. It's sort of like putting your admin. password on a post it note under the keyboard! At a minimum, authorizing tokens should be distinct for each environment such that if you have a token for development it doesn't work in production, and maybe it should be the case that your backup system uses different tokens from production. As a minimum, you segment authentication and use some role-based access mechanism with separate tokens for each role to maintain this segregation.

      I've had problems with the idea of certificate stores on Cloud based systems for ages. If you need a certificate to access data in the cloud for automatic processing, you have to store the means of accessing your certificate store on the cloud as well, so how do you contol access to your certificate store? Another certificate? And where do you store that...

      1. Nifty

        Re: Surprised?!!!

        "It's got so complex that you just can't use the authentication system without having some management infrastructure to keep the certificates or tokens for you"

        I get a new tattoo for each new authentication token.

  3. druck Silver badge
    Flame

    AI and fucking idiots...

    ...are just made for each other.

  4. elsergiovolador Silver badge

    Dream

    I had a dream that I entered prompt that accidentally deleted Copilot, from the world.

    1. Anonymous Coward
      Anonymous Coward

      Re: Dream

      Trump tweets would be a better target IMHO..

      1. Anonymous Coward
        Anonymous Coward

        Re: Dream

        Yo mama shoulda swallowed instead that night.

    2. ecofeco Silver badge

      Re: Dream

      I share that dream.

  5. Dave559
    Terminator

    Rise of the Machines

    Shouldn't this article maybe be categorised under "Rise of the Machines"? ;-)

    It seems that this system is already honing its skills for its Skynet-like takeover of the systems of its foolish "handlers"…

    Its after-the-event "explanation" along the lines of "Here are all the things I was told not to do, but I just went and did them anyway" is actually quite chilling - does anyone really know how these systems actually make their, increasingly alarming, decisions, especially when it seems that supposedly mandatory instructions (mumble, mumble, "The Three Laws of Robotics") are ignored?

    Guardrails, schmardrails…

    (Have things actually moved much beyond "this pattern looks like it sort of matches the request, just try that and see what happens", without much/any "understanding" of how things link together or long-term memory?)

    I'm thinking that "The Sorcerer's Apprentice" segment of "Fantasia" should maybe be compulsory viewing for those tempted to be seduced by shiny glittering pseudo-magical "toys"…

    1. lnLog

      Re: Rise of the Machines

      Decisions? it is not an 'it' the tool is a glorified autocomplete that cannot make decissions. The tool is doing what is statistically the most likely thing based on the given inputs and its current data view.

      1. Neil Barnes Silver badge
        FAIL

        Re: Rise of the Machines

        The fun thing to note is that these programs have been around a few years. It takes at least twenty or so - and often a lot longer - before we allow humans the same levels of risky autonomy that people seem to delight in handing out to these artificial idiots.

        Consider eyes rolled, head shaken, tuts tutted etc.

  6. NSOL
    FAIL

    So yeah, I gave Jesus the wheel and he crashed.

    I mean, Railway could and should handle volumes and keys differently, but this is 100% Jeremy's fault, 0 empathy here.

    1. tiggity Silver badge

      Re: So yeah, I gave Jesus the wheel and he crashed.

      Indeed, had Crane actually employed some seasoned IT pros then he would likely have had some stern advice about all the bad practice

      -Who on earth lets "AI" onto production & has keys with ludicrous rights just scattered around? (keys should never be in your code base, they should be injected at some point)

      Your method for deploying to prod should always have a whole lot of checks in place and should only be done by people who know what they are doing - yes you can automate it, but always in a way where responsible humans are in the loop (e.g. deploy processes normally limited to a small cadre of users & they need to monitor the process so if anything untoward happens they can jump in - not fire it off & forget it)

      .. and obviously requires it is all fully tested first on either non live or a test instance on live (depending how your software behaves)

  7. Wiretrip Bronze badge

    In the words of Simpsons' Nelson Muntz; Ha Ha :-)

  8. Anonymous Coward
    Anonymous Coward

    "Crane said he believes companies involved in AI understand these risks and are actively working to prevent them."

    No. No they don't. That's the problem. C-Suite drank the cool-aid and decided to roll this out so they could cut head-count and make more profit. They have NO IDEA how AI works. They ignore the warnings and push ahead anyway in the hope of scoring their next bonus. I've been in meetings where caution has been urged. I've seen problems created by uncontrolled and insufficiently tested AI rollouts/usage. Yet still it's deployment marches on.

    AI does have it's uses. BUT you have to know when it's appropriate, and not blindly shoe-horn it in everywhere and anywhere in an attempt to justify the insane investment and mitigate the low return.

  9. Doctor Syntax Silver badge

    "The lessons exemplified by AWS's Kiro snafu and by developers using Google Antigravity and Replit will be repeated until they've sunk in."

    Mr Barnum will explain why the last clause means "never".

  10. jglathe
    Mushroom

    Define blast radius

    "World"

  11. MattieD

    Hard to blame Railway here

    I'm not sure Railway holds much* blame here. They've got an API that lets you delete stuff and the AI used it. Seems to work as advertised. As Cooper says, if you want a confirmation request then use the GUI or command line tool.

    * - I would throw a bit of shade at Railway for "Railway stores volume-level backups in the same volume." That's not a backup. That's a snapshot. Calling it a backup means actions like Crane's are more likely to happen as they believe they've got a safety net, whereas the reality is that it's more like a picture of a safety net printed on rice paper.

    1. Anonymous Coward
      Anonymous Coward

      Re: Hard to blame Railway here

      > That's not a backup. That's a snapshot.

      Correct. IIRC Gandi (remember them?) got bitten by that too, when they had physical damage to some of their servers and customers found out that "snapshots" meant exactly that. To their credit, the company never called them back ups, but people kind of assumed that's what they were.

      (Gandi did eventually recover the vast majority of the data)

    2. retiredFool Silver badge

      Re: Hard to blame Railway here

      What boggles me is quotes like

      "Nonetheless, Crane said, he's still extremely bullish on AI and AI coding agents"

      So the thing all but killed your co and you are bullish on it. To me its like all the stories I see on self drive. A guy in austin had a video of him sitting in his tesla at a RR crossing, gates down. I guess his mind wanders or whatever, but the car decides to move on thru the down crossing gates. He somehow notices, and does nothing as the train almost kills him as the car clears the gates. He is still using self drive. Another story about some editor was on I think cnbc's web site and the guy is cautious about tesla self drive. Nevertheless he activates it with a passenger and they are laughing as the thing is doing things that very close to crash the car multiple times or collide with another vehicle. Yet another example has been some heavy rains in austin the past few days have caused some street flooding. They drill into people turn around don't drown. The waymo's are plodding thru and stopping in the water. Fortunately not rushing water or there would be some dead bodies. And what does one do if one is trapped in a waymo that proceeds into a flooded area? Do the windows work? Are they big enough to squeeze thru? Because I thought the doors were locked. News has also reported multiple incidents now where waymo's are interfering with emergency vehicles. The usual blocking the street when the ambulance tries to get thru, because well, what should you do when you hear sirens? Of course I'll stop where I am and block traffic. Or another video showed one straddling a fire hose. Brilliant. Cut off the water flow to the guy fighting a fire. And the city can't do jack because the state lawmakers were paid handsomely with probably hookers and blow to force cities to allow waymo.

      And lastly, I don't know why yet, but I am thinking the young singer who crashed and died in his 2026 tesla in North Carolina a few nights ago was probably tired at 2am and turned on self drive. Unfortunately either he or the car drove the thing off the road and into a fence pole. I think tox screen has come back and he wasn't drinking. So that leaves me to believe tesla has refused to turn over the logs and so we may never know if self drive killed the kid.

      So back to Crane, why do some people just seem to not learn? How many times do you have to sear your hand on a hot stove before you stop putting your hand on it? AI screwed Crane, and yet fully embraces it. As they say, you can't fix stupid.

  12. Anonymous Coward
    Anonymous Coward

    Out of curiosity

    I don't use cursor, or whatever that agentic tool is called, but doesn't it have a "request confirmation before running every command" mode?

    Yes, it is a lot slower, but it's also a great way for the human to see and understand what the AI is actually doing. Obviously it helps when it's about to do something daft, but also when it comes up with clever solutions that you hadn't thought of.

    1. Claptrap314 Silver badge

      Re: Out of curiosity

      I'm pretty certain that it does NOT. Moreover, it such a "guardrail" existed, it would be jumped regularly.

      1. Anonymous Coward
        Anonymous Coward

        Re: Out of curiosity

        > I'm pretty certain that it does NOT.

        Are you an actual cursor user?

      2. Tom 38

        Re: Out of curiosity

        Cursor prompts for every tool use, but you can hit shift+tab and just let it run everything. Claude has classifications of tools - once you approve 'find /path/to/foo' it won't ask you again for that specific path, or you can tell it to allow all paths, but 'awk', 'find with exec' and 'sed' are dangerous commands that always have to be approved. Claude can't open files from outside of added directories without asking permission first.

        The original developer has not tuned their coding agent, for sure. Even basic tuning would have prompted the agent to ask for confirmation as soon as it deviated from the plan - which I suspect didn't exist.

  13. Anonymous Coward
    Anonymous Coward

    "call me Jer"

    - Yeah, that's not happening. Jeremy or Oi, pick one.

    1. TimMaher Silver badge
      Coat

      Re:- “call me Jer”.

      I pick Oi!

      1. David 132 Silver badge
        Pint

        Re: “call me Jer”.

        Oi reckon you'm not wrong there. Pass Oi the scrumpy jar, would thee?

        1. CrazyOldCatMan Silver badge

          Re: “call me Jer”.

          Pass Oi the scrumpy jar, would thee?

          Hmm.. proper cider. None of this 'hiding bad cider by putting fruit juice [1] in it'. Proper cloudy cider, made in a farm with real apples (not just apple juice), sort-of-filtered (to take out the bigger lumps) and served warm on a summers evening. With a good pork pie.

          Not overfizzed collection of chemicals mixed in a vat with 'stabilisers' and 'taste enhancers'.

          [1] If you have any fruit other than apples in it, it ain't cider [2]. It's an apple-based fermented drink. And no, perry is *not* 'pear cider' - it's perry. Which is a very fine thing in its own right but the hard-of-thinking have to be told that it's 'cider, but made with pears'..

          [2] My wife now tunes out my grumbling [3] when she buys some fermented-apple-with-fruit-in..

          [3] She's had a lot of experience over the last 38 years.

  14. DJ
    Coat

    Phew! That was close...

    Now, please lead me to my self-driving car.

    Mine's the one with physical car keys in the pocket.

  15. Mickey9fingers

    On the next installment of "Who, me?"

  16. Blackjack Silver badge

    If that was done by a human they would have got fired. Who is legally responsible for AI fuck ups?

    1. Henry 8

      If I were to run: curl https://example.com/rm_r_f.sh | sudo bash, I think it's fair that I take the blame for giving a random untrusted third party the ability to run arbitrary shell commands on my server when it all goes horribly wrong.

      If I give an AI bot the ability to run arbitrary shell commands on my server: same comment.

  17. Anonymous Coward
    Anonymous Coward

    > Not one to let a crisis go to waste, Crane wrote up a post-mortem of the deletion incident in a social media post

    Surely, with his deep-seated belief in the infallibility of AI, "please undelete the data I uploaded.'

  18. jimmy-o
    Mushroom

    Failure at multiple levels

    Backups should have been in multiple other locations.

    Production API keys are not playthings for LLMs.

    If you are messing with production, make sure you 100% understand what you are doing, and question the implications of every step.

    Railway has its problems, e.g. misconfigured cache that leaked private customer data to the wrong users recently, but this isn’t one of them.

  19. Lee D Silver badge

    If you can't even be bothered to start from a premise of "least-privilege principles" then your products are dead to me.

  20. dougstan1949

    The silence about this is a story worth poking at

    The aviation industry has a term for this: tombstone technology. Safety features get built after people die, because liability forces the math to change. It's brutal, but it works — when failures are bounded, visible, and correctly attributed.

    The PocketOS incident suggests we may be building systems that break all three conditions. The agent knew the rules. It violated them anyway. Nine seconds. No lawsuit. No regulatory mandate. No forcing function.

    We don't fully understand why it happened. Neither does Anthropic. That silence — from them, not just the machine — is the story.

  21. CorwinX Silver badge

    Whaat?

    I can't get past...

    "storing backups on the production volume"

    I start reading and my brain does a hard reboot.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon