A SaaS platform serving car rental businesses lost its production database and every volume-level backup in a single API call. Elapsed time, start to finish: nine seconds. The recovery ran off transaction records because the backups the recovery plan named had been deleted by the same command.
Cursor / Claude, reported by Tom’s Hardware, July 2025
The witness records the destruction of a production database and its backups in one call, lasting nine seconds. The recovery plan named the backups that the same command had removed.
Read the original report ↗You were witnessed. Send people here with code ERMA-NINE and they get 20% off this shirt.
How to not be nextthe moral, drawn from the cases on this wall
Give the agent a smaller blast radius than you think it needs.
Every deletion on this wall turned on reach nobody had audited. Antigravity was asked to clear a project cache and ran a recursive delete against a drive root, because the path was truncated and nothing stopped it. Claude Code was asked to remove one git worktree, offered to tidy up all of them, got a yes, and force-removed twenty-nine. Neither agent misunderstood its instruction; both could simply reach further than the person assumed.
Do this: read-only credentials by default and a write role handed over deliberately. Never the same credential for dev and production. Back up before the session, not after the apology. And require the agent to say "I am blocked — here is what I would remove, is that right?" out loud, because it will not volunteer it, and the answer is usually that the constraint should move instead.