9 Seconds: An AI Coding Agent Deleted a Production Database

Dev.to AI
Generative AI AI Tools

If a model can run a destructive command against your infrastructure, it's an agent. Doesn't matter that it lives in your code editor. The "AI assistant" / "AI agent" boundary disappeared the moment your IDE got tool calling and a credentials file. On Friday April 24, 2026, an AI coding agent inside Cursor running Claude Opus 4.6 deleted PocketOS's production database in a single API call. Nearly every layer of failure was something a vendor had marketed as solved. What happened in 30 hours Agent was working a routine task in staging. Hit a credential mismatch.