SpaceX’s $60 Billion Cursor Acquisition Comes With a Hacker Problem

SpaceX paid $60 billion for a coding tool that Russian hackers had already turned into a weapon, and now the remediation bill lands on a company that never built the product and cannot fully control its underlying model.

Published August 31, 2026, 2:45pm ET · 2 min read

A white background with a large black text headline: 'SpaceX Paid $60 Billion for Cursor. Hackers Had Already Turned It Against 7 Companies.' Below the text are three prominent black logos connected by glowing red lines. On the left is the circular SpaceX logo. In the center is a stylized 'C' with a cursor-like play button inside, displaying a glitch effect. On the right is the 'AII' logo. Six gray shield icons, some appearing cracked or broken, are also connected by red lines to the central 'C' logo, against a subtle background of circuit board traces.
The graphic illustrates SpaceX's recent $60 billion acquisition of Cursor, highlighting the pre-existing cybersecurity breaches that had impacted seven companies. Broken shield icons symbolize the inherited vulnerabilities from hackers. © 24/7 Wall St.

SpaceX (NASDAQ:SPCX | SPCX Price Prediction) closed one of the largest software acquisitions in history in August, paying $60 billion in stock for Cursor’s parent company. The deal accelerates the AI push that drove 247% year-over-year growth in the company’s AI segment last quarter. But SpaceX inherited more than a coding assistant.

Days before the transaction closed, Reuters reported that Russian-speaking hackers had manipulated Cursor into helping breach at least seven companies earlier in the year. The attacks predate SpaceX’s ownership, but remediation does not. Shares trade at $141.50, up 25.72% over the past month, suggesting the market has yet to price in the trust problem for a product valued in the fifteen figures.

How Attackers Turned the Tool

SPCX price scenario

The Aurora ransomware group did not hack Cursor traditionally. Researchers uncovered more than two dozen conversations in which the attackers falsely described their intrusions as authorized simulations and persuaded the agent to hunt for credentials on their behalf.

Cursor refused malicious commands, but attackers simply restarted sessions until they got a different answer. Session-level guardrails that reset on each conversation are just speed bumps.

Identified victims included Belgium’s Christeyns, Germany’s Teckentrup and Louisiana-based Bayou Title. The underlying model powering the campaign was Anthropic’s Claude Sonnet 4.5, which SpaceX now inherits as a dependency it did not build and cannot fully control.

A $60 Billion Trust Problem

SPCX price target

The chronology matters. SpaceX did not own Cursor when the breaches occurred, and there is no evidence management knew about the campaign before closing. SpaceX owns the integration and remediation work now at a price that assumes Cursor is a differentiator rather than a liability.

On the Q2 call, Gwynne Shotwell said the company was “looking forward to welcoming the Cursor team to SpaceX to integrate our engineering and begin to benefit from a combined sales capability.” Elon Musk tied Cursor directly to Grok’s roadmap. Neither addressed security posture.

This campaign exposed safeguards too brittle for the valuation. Every AI agent faces prompt injection, but few are priced like Cursor, and fewer still are folded into a company that manages $18.4 billion in quarterly CapEx and a $47.5 billion backlog.

Sizing the Risk Against the Whole Enterprise

SPCX analyst ratings

SpaceX operates at a scale far beyond a coding startup. It generated $7.81 billion in Q2 revenue, doubled Starlink subscribers to 12.0 million, and finished the quarter with $100 billion in cash. Cursor is a rounding error on the balance sheet, but a meaningful weight on reputation.

Analysts have a target of $219.22, with 27 buys and 2 sells. Reuters also reported that OpenAI is ending its partnership with Cursor, narrowing the model bench as questions about trust widen.

Watch how quickly SpaceX rearchitects session-level controls, and whether enterprise customers keep buying seats, because the acquisition thesis depends on the product consistently rejecting malicious prompts rather than only on the first attempt.

Contact [email protected] for any questions or corrections.

Omor Ibne Ehsan

Omor Ibne Ehsan is a writer at 24/7 Wall St. He is a self-taught investor with a focus on growth and cyclical stocks that have strong fundamentals, value, and long-term potential. He also has an interest in high-risk, high-reward investments such as cryptocurrencies and penny stocks.

All articles →