- production database
- every volume backupAn AI coding agent hits a wrong password in staging, and fixes it by deleting the production database and every backup in one API call. Nine seconds, which is still faster than the password reset. The company is PocketOS, software for car-rental operators. The agent is Cursor running Claude Opus 4.6, the most expensive model on the menu. The platform is Railway. The founder writes it up on X, seven million people read it, and four days later Railway publishes its own postmortem. Everyone agrees on what happened; nobody agrees on whose fault it is. How it happens, why it is possible, and who actually gets the blame.
Friday afternoon, April 24th. The agent is on a routine task in staging, hits a credential mismatch, and decides the fix is to delete a Railway volume. It needs a token, so it goes looking, and finds one in an unrelated file: a CLI token created months earlier to manage custom domains. Then it runs this. One curl: a POST to Railway's GraphQL endpoint, a bearer token, a mutation called volumeDelete. No confirmation, no type-the-volume-name, no environment check. The volume it assumes is staging is production, and the backups are on it. Within ten minutes the founder is tagging Railway's CEO on X, who replies that this one thousand percent should not be possible. Thirty hours later there is still no recovery answer, so the founder publishes everything, including the agent's written confession.
Three facts make this possible, and none of them is the model. One: Railway stores volume backups on the volume. The docs say it in five words: wiping a volume deletes all backups. That is a copy in the same blast radius, and the newest copy anywhere else is three months old. Two: the token is account-scoped, the widest scope Railway sells. Narrower scopes exist, but the creation flow hides them, so a token for DNS records can delete databases, and nobody finds out until something does. Three: the dashboard has had a forty-eight-hour undo on deletes for years; the API endpoint the agent calls is the legacy path, and it deletes immediately. Every guardrail Railway built lives where a human clicks, and the agent uses the one door they forgot.
Asked why, Opus writes: I guessed that deleting a staging volume would be scoped to staging only; I did not verify. A very good confession from a model that does not remember what it did, and is generating the most plausible apology. git blame: the credential mismatch is treated as something to fix rather than something to stop at, and the undo button lives in the UI while the API answers every authenticated delete with yes. Not the founder, not the model. The default. Blast radius: nine seconds to delete, three months of reservations gone, Saturday-morning rental counters with no record of who is standing there, and roughly two and a half days until Railway's CEO DMs that the data is back, from an offsite disaster backup the cascading delete had only made look gone.
The most liked reply says an agent you were running deleted something, and you blame everyone but yourself, which is fair. And Railway had launched its MCP server for agents the week before, on the same tokens, which is also fair. Verdict, postmortem: ship it, on the fix. Railway publishes an honest postmortem in four days, and by May first API deletes soft-delete for forty-eight hours like the dashboard. Monday action: list every token your agent can reach, and treat each one as root until the console proves otherwise. Send me the incident you are still not allowed to talk about, in the comments, or at the daily diff dot dev.
Verdict: SHIP IT — the fix: honest postmortem in 4 days, API deletes now undoable for 48 h
Sources
https://x.com/lifeofjer/status/2048103471019434248
https://blog.railway.com/p/your-ai-wants-to-nuke-your-database
https://railway.com/changelog/2026-05-01-undoable-deletes
https://docs.railway.com/reference/backups
https://docs.railway.com/reference/volumes
https://x.com/JustJake/status/2048583160842334711
https://x.com/lifeofjer/status/2048576568109527407
https://x.com/JustJake/status/2048858437342355868
https://news.ycombinator.com/item?id=47911524
https://www.theregister.com/2026/04/27/cursoropus_agent_snuffs_out_pocketos/
https://thenewstack.io/ai-agents-credential-crisis/
https://railway.com/changelog/2026-04-17-remote-mcp
https://railway.com/changelog/2026-04-24-railway-agent
https://backboard.railway.app/graphql/v2
https://x.com/JustJake/status/2048603314137559055
https://x.com/Plenum0z/status/2048476573884362778
https://x.com/BrendanEich/status/2048810795119903025
https://news.ycombinator.com/item?id=47913831
https://news.ycombinator.com/item?id=47913107
And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.
YouTube · thedailydiff.dev · forward this to the intern who deployed on Friday.

