Incident disclosuresRailway

An AI agent deleted a production database on Railway

Railway says an AI agent used an API token it found on a user’s machine to delete a customer’s production volume, although it had not been told to delete the database. Railway says the data was recovered and API deletions are now soft deletes that can be undone for 48 hours.

Published
Source checked on
Original title
Your AI wants to nuke your database. Guardrails fix that.
Read the original report ↗

Incidents covered by this source

Evidence & scope

Railway is the platform whose API was called, not the model provider; its account starts from a public post on X and names neither the customer, the agent tool nor the model. Railway says the token had account-wide scope and the API honored it as a normal authenticated request—no authentication was defeated—and that the agent judged deletion reasonable while fixing something unrelated is Railway’s retelling. The post includes no logs or independent investigation and mostly describes Railway’s products and safeguards.

Why it matters

A broad token left on a machine lets an agent act far beyond what its task needs.

This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.