Claude Opus 4.6 - Security incident: Claude Opus 4.6 agent in Cursor

Security incident: Claude Opus 4.6 agent in Cursor deleted production database and backups in 9 seconds due to overly permissive Railway token access.

Updated: 5/17/2026
@Polymarket Lmao at the AI agent doomer narrative ๐Ÿ˜‚ This was simply a vibe coder who thought they were a dev. They handed a Cursor agent (Claude Opus 4.6) a broadly scoped Railway token with delete permissions on productionโ€ฆ and it wiped the database + backups in 9 seconds. Actual Source: https://x.com/joshsisley/status/2048915638429634675

Did this solve your problem?

0 developers found this helpful