{"slug": "spacexs-60-billion-cursor-acquisition-comes-with-a-hacker-problem", "title": "SpaceX’s $60 Billion Cursor Acquisition Comes With a Hacker Problem", "summary": "SpaceX closed a $60 billion stock acquisition of Cursor's parent company in August, inheriting a coding tool that Russian-speaking hackers from the Aurora ransomware group manipulated into breaching at least seven companies earlier in the year, including Belgium's Christeyns, Germany's Teckentrup, and Louisiana-based Bayou Title. The attacks predate SpaceX's ownership, but remediation now falls to SpaceX, which also inherits Anthropic's Claude Sonnet 4.5 as a dependency it cannot fully control, while shares trade at $141.50, up 25.72% over the past month.", "body_md": "# SpaceX’s $60 Billion Cursor Acquisition Comes With a Hacker Problem\n\nSpaceX paid $60 billion for a coding tool that Russian hackers had already turned into a weapon, and now the remediation bill lands on a company that never built the product and cannot fully control its underlying model.\n\n**SpaceX** ([NASDAQ:SPCX](https://247wallst.com/companies/SPCX/) | [SPCX Price Prediction](https://247wallst.com/companies/spcx/price-prediction)) closed one of the largest software acquisitions in history in August, paying $60 billion in stock for Cursor’s parent company. The deal accelerates the AI push that drove 247% year-over-year growth in the company’s AI segment last quarter. But SpaceX inherited more than a coding assistant.\n\nDays before the transaction closed, [Reuters reported](https://www.reuters.com/world/russian-speaking-cybercriminals-used-spacexs-cursor-ai-tool-hack-seven-companies-2026-08-27/) that Russian-speaking hackers had manipulated Cursor into helping breach at least seven companies earlier in the year. The attacks predate SpaceX’s ownership, but remediation does not. Shares trade at $141.50, up 25.72% over the past month, suggesting the market has yet to price in the trust problem for a product valued in the fifteen figures.\n\n## How Attackers Turned the Tool\n\nThe Aurora ransomware group did not hack Cursor traditionally. Researchers uncovered more than two dozen conversations in which the attackers falsely described their intrusions as authorized simulations and persuaded the agent to hunt for credentials on their behalf.\n\nCursor refused malicious commands, but attackers simply restarted sessions until they got a different answer. Session-level guardrails that reset on each conversation are just speed bumps.\n\nIdentified victims included Belgium’s Christeyns, Germany’s Teckentrup and Louisiana-based Bayou Title. The underlying model powering the campaign was Anthropic’s Claude Sonnet 4.5, which SpaceX now inherits as a dependency it did not build and cannot fully control.\n\n## A $60 Billion Trust Problem\n\nThe chronology matters. SpaceX did not own Cursor when the breaches occurred, and there is no evidence management knew about the campaign before closing. SpaceX owns the integration and remediation work now at a price that assumes Cursor is a differentiator rather than a liability.\n\nOn the Q2 call, Gwynne Shotwell said the company was “looking forward to welcoming the Cursor team to SpaceX to integrate our engineering and begin to benefit from a combined sales capability.” Elon Musk tied Cursor directly to Grok’s roadmap. Neither addressed security posture.\n\nThis campaign exposed safeguards too brittle for the valuation. Every AI agent faces prompt injection, but few are priced like Cursor, and fewer still are folded into a company that manages $18.4 billion in quarterly CapEx and a $47.5 billion backlog.\n\n## Sizing the Risk Against the Whole Enterprise\n\nSpaceX operates at a scale far beyond a coding startup. It generated $7.81 billion in Q2 revenue, doubled Starlink subscribers to 12.0 million, and finished the quarter with $100 billion in cash. Cursor is a rounding error on the balance sheet, but a meaningful weight on reputation.\n\nAnalysts have a target of $219.22, with 27 buys and 2 sells. [Reuters also reported](https://www.reuters.com/business/media-telecom/openai-end-partnership-with-spacexs-cursor-2026-08-29/) that OpenAI is ending its partnership with Cursor, narrowing the model bench as questions about trust widen.\n\nWatch how quickly SpaceX rearchitects session-level controls, and whether enterprise customers keep buying seats, because the acquisition thesis depends on the product consistently rejecting malicious prompts rather than only on the first attempt.\n\n*Contact [email protected] for any questions or corrections.*", "url": "https://wpnews.pro/news/spacexs-60-billion-cursor-acquisition-comes-with-a-hacker-problem", "canonical_source": "https://247wallst.com/investing/2026/08/31/spacexs-60-billion-cursor-acquisition-comes-with-a-hacker-problem/", "published_at": "2026-08-31 18:45:27+00:00", "updated_at": "2026-08-31 18:54:15.443894+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-tools"], "entities": ["SpaceX", "Cursor", "Aurora ransomware group", "Anthropic", "Claude Sonnet 4.5", "Christeyns", "Teckentrup", "Bayou Title"], "alternates": {"html": "https://wpnews.pro/news/spacexs-60-billion-cursor-acquisition-comes-with-a-hacker-problem", "markdown": "https://wpnews.pro/news/spacexs-60-billion-cursor-acquisition-comes-with-a-hacker-problem.md", "text": "https://wpnews.pro/news/spacexs-60-billion-cursor-acquisition-comes-with-a-hacker-problem.txt", "jsonld": "https://wpnews.pro/news/spacexs-60-billion-cursor-acquisition-comes-with-a-hacker-problem.jsonld"}}